SY0-701 Security Operations Practice Question
An investigator needs a copy of a suspect laptop drive for analysis without changing the original media. What should be used?
⚠ Common exam trap
A common mix-up: candidates confuse a simple file copy or archive with a forensically sound image, overlooking the need for a bit-for-bit copy and write protection to preserve evidence integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A full forensic image taken with a write blocker
A full forensic image taken with a write blocker is the correct method because it creates a bit-for-bit copy of the entire drive, including all partitions, unallocated space, and metadata, without altering the original media. The write blocker hardware or software ensures that no write commands reach the suspect drive, preserving its integrity for legal and evidentiary purposes. This approach is required by forensic standards such as NIST SP 800-86 and ensures the copy is admissible as evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A simple file copy of the user folder
Why it's wrong here
A simple file copy of the user folder replicates only the logical file hierarchy, omitting critical file system metadata such as the Master File Table (MFT), alternate data streams, and resident attributes. It also fails to include unallocated space and deleted files that may contain recoverable evidence, and the copying process updates access times on the source media. This approach does not produce a byte-for-byte duplicate, so it is insufficient for forensic analysis.
- ✓
A full forensic image taken with a write blocker
Why this is correct
This is the best answer because a forensic image creates a bit-for-bit copy of the drive while a write blocker prevents accidental changes to the original media. That combination preserves evidentiary integrity and allows the investigator to analyze the copy safely. It is the standard approach when the original disk may later be needed in court or for formal review.
- ✗
A compressed archive of the desktop contents
Why it's wrong here
A compressed archive, such as a ZIP or 7-Zip, only collects files visible through the live operating system's file system at the moment it is created. It does not capture unallocated space, file slack, or deleted file remnants, and the compression process itself can alter timestamps and other metadata. Because the archive lacks the disk's full bit-level structure, it cannot serve as a forensic copy or support later recovery of hidden or deleted evidence.
- ✗
The original drive mounted normally on the investigator machine
Why it's wrong here
Mounting the original drive in a normal, read-write fashion exposes evidence to unintended modifications from the operating system's journaling, prefetch, and access-time updates, and it can trigger writes to the hibernation or page file. Even a read-only mount may cause subtle changes due to file system mounting routines, and it allows the drive's controller to remap or modify metadata. This alters the original media, breaking the chain of custody and making the evidence inadmissible.
Go deeper
Related to this question
Learn chapter
Network Forensics and Packet Analysis
Key term
Forensic image
A forensic image is an exact, bit-for-bit copy of a storage device, including all deleted and hidden data, created and preserved for digital investigation.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.