SY0-701 Security Operations Practice Question
An investigator must collect data from a suspected insider-threat laptop so the evidence could be used in an HR and legal review. Which action best preserves admissibility?
⚠ Common exam trap
Watch out — candidates often think booting normally or copying files is sufficient for evidence collection, but the exam emphasizes that any action that modifies the original media breaks the chain of custody and makes evidence inadmissible in legal proceedings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a forensic image through a write blocker and record hashes before and after acquisition
Creating a forensic image through a write blocker ensures the original evidence is not altered, preserving its integrity for admissibility in HR and legal proceedings. Recording hashes before and after acquisition allows verification that the image is an exact, unmodified copy, which is critical for chain of custody and meeting legal standards such as Daubert or Federal Rules of Evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Boot the laptop normally and browse the user's files for clues
Why it's wrong here
Booting the laptop normally and browsing files causes the operating system to update file system metadata—such as last-accessed timestamps, NTFS $LogFile records, and the UsnJrnl—and to write temporary files, registry hives, and pagefile data to the disk. These changes alter the original evidence, invalidating a forensic hash and breaking chain of custody. A live browse also risks triggering malware or encryption locks that could destroy the very data the investigator needs to preserve.
- ✓
Create a forensic image through a write blocker and record hashes before and after acquisition
Why this is correct
This is the correct preservation method because it avoids altering the original disk and creates verifiable integrity checks. Using a write blocker prevents writes to the source media, and hashes document that the image matches the evidence. Detailed chain-of-custody records then support admissibility in HR, disciplinary, or legal proceedings.
- ✗
Copy the user's documents to a USB drive and continue the investigation later
Why it's wrong here
Copying selected user documents to a USB drive is not a forensic acquisition because it does not capture deleted files, slack space, unallocated clusters, or alternate data streams, all of which may contain critical insider-threat artifacts. Reading files from a live system also updates last-accessed times, tainting metadata, and the copy process itself can modify the USB's file system without a write blocker. A proper acquisition requires a sector-level image of the entire media, not a logical copy of specific items.
- ✗
Take screenshots of the desktop and delete the original drive contents afterward
Why it's wrong here
Screenshots merely capture a subset of what is displayed on screen, omitting hidden files, the registry, browser history, deleted artifacts, and volatile data such as running processes and network connections. Deleting the original drive contents after taking screenshots destroys the only source material, making it impossible to recover evidence or verify its authenticity through hashes. This action constitutes spoliation and is both technically and legally fatal to any subsequent HR, civil, or criminal proceeding.
Go deeper
Related to this question
Learn chapter
Chain of Custody in Digital Forensics
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.