Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

An investigator must collect data from a suspected insider-threat laptop so the evidence could be used in an HR and legal review. Which action best preserves admissibility?

⚠ Common exam trap

Watch out — candidates often think booting normally or copying files is sufficient for evidence collection, but the exam emphasizes that any action that modifies the original media breaks the chain of custody and makes evidence inadmissible in legal proceedings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a forensic image through a write blocker and record hashes before and after acquisition

Creating a forensic image through a write blocker ensures the original evidence is not altered, preserving its integrity for admissibility in HR and legal proceedings. Recording hashes before and after acquisition allows verification that the image is an exact, unmodified copy, which is critical for chain of custody and meeting legal standards such as Daubert or Federal Rules of Evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Boot the laptop normally and browse the user's files for clues

    Why it's wrong here

    Booting the laptop normally and browsing files causes the operating system to update file system metadata—such as last-accessed timestamps, NTFS $LogFile records, and the UsnJrnl—and to write temporary files, registry hives, and pagefile data to the disk. These changes alter the original evidence, invalidating a forensic hash and breaking chain of custody. A live browse also risks triggering malware or encryption locks that could destroy the very data the investigator needs to preserve.

  • Create a forensic image through a write blocker and record hashes before and after acquisition

    Why this is correct

    This is the correct preservation method because it avoids altering the original disk and creates verifiable integrity checks. Using a write blocker prevents writes to the source media, and hashes document that the image matches the evidence. Detailed chain-of-custody records then support admissibility in HR, disciplinary, or legal proceedings.

  • Copy the user's documents to a USB drive and continue the investigation later

    Why it's wrong here

    Copying selected user documents to a USB drive is not a forensic acquisition because it does not capture deleted files, slack space, unallocated clusters, or alternate data streams, all of which may contain critical insider-threat artifacts. Reading files from a live system also updates last-accessed times, tainting metadata, and the copy process itself can modify the USB's file system without a write blocker. A proper acquisition requires a sector-level image of the entire media, not a logical copy of specific items.

  • Take screenshots of the desktop and delete the original drive contents afterward

    Why it's wrong here

    Screenshots merely capture a subset of what is displayed on screen, omitting hidden files, the registry, browser history, deleted artifacts, and volatile data such as running processes and network connections. Deleting the original drive contents after taking screenshots destroys the only source material, making it impossible to recover evidence or verify its authenticity through hashes. This action constitutes spoliation and is both technically and legally fatal to any subsequent HR, civil, or criminal proceeding.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.