Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

After a suspicious laptop is imaged with a write blocker, the original drive is sealed and stored. Before a second analyst examines the image, what is the most important next step to preserve admissibility?

⚠ Common exam trap

CompTIA often tests the misconception that renaming or copying evidence is a valid step for preservation, when in fact the core legal requirement is maintaining integrity verification and chain-of-custody documentation before any further handling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document the transfer in the chain-of-custody log and verify the image hash still matches the acquisition value.

Before a second analyst accesses the image, the most critical step is to update the chain-of-custody log to document the transfer of custody and to verify the integrity of the image by comparing its current hash value against the original acquisition hash. This ensures that the evidence has not been altered or corrupted since it was first imaged, which is essential for maintaining admissibility in legal proceedings under rules such as the Federal Rules of Evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mount the image read/write so the analyst can browse faster.

    Why it's wrong here

    Mounting the image read/write—even just to 'browse faster'—can alter file system metadata such as access timestamps or trigger journal writes, which changes the hash and may render the evidence inadmissible. A forensic examiner should always mount evidence images in a read-only environment or use a forensic tool that blocks writes; otherwise, the very act of analysis can destroy the integrity the hash verifies. This is a fundamental violation of forensic soundness, as the acquisition hash no longer matches the current state.

  • Copy the image to a USB drive for easier transport.

    Why it's wrong here

    Copying the image to an unsecured USB drive for transport introduces a physical break in the chain of custody: there is no documented, verifiable transfer that the evidence remained unchanged and was not intercepted, lost, or tampered with during movement. USB drives are also prone to malware, accidental corruption, or being misused, and without a contemporaneous hash verification at the destination, you cannot prove the copy matches the original. Proper handling requires a secure, logged transfer using a controlled device and re-verification of the hash to maintain continuity.

  • Document the transfer in the chain-of-custody log and verify the image hash still matches the acquisition value.

    Why this is correct

    Chain-of-custody documentation shows who handled the evidence, when it changed hands, and why. Verifying the image hash against the acquisition hash proves the data has not changed since collection. Together, these steps support integrity and admissibility in administrative, HR, or legal reviews. A well-maintained log plus matching hashes is the standard way to show the evidence remained untampered during transfer and analysis.

  • Rename the evidence file to match the case number.

    Why it's wrong here

    Renaming the evidence file to match the case number is a purely cosmetic change that does not demonstrate that the data's integrity was preserved, nor does it record who had access or why. In fact, changing the filename could be perceived as an attempt to alter evidence or could break internal metadata references, potentially raising questions during legal review. Chain of custody is established through documented handling logs and cryptographic hash verification, not by file naming conventions.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.