Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

An investigator needs a copy of a suspect laptop drive for analysis without changing the original media. What should be used?

⚠ Common exam trap

A common mix-up: candidates confuse a simple file copy or archive with a forensically sound image, overlooking the need for a bit-for-bit copy and write protection to preserve evidence integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A full forensic image taken with a write blocker

A full forensic image taken with a write blocker is the correct method because it creates a bit-for-bit copy of the entire drive, including all partitions, unallocated space, and metadata, without altering the original media. The write blocker hardware or software ensures that no write commands reach the suspect drive, preserving its integrity for legal and evidentiary purposes. This approach is required by forensic standards such as NIST SP 800-86 and ensures the copy is admissible as evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A simple file copy of the user folder

    Why it's wrong here

    A simple file copy of the user folder replicates only the logical file hierarchy, omitting critical file system metadata such as the Master File Table (MFT), alternate data streams, and resident attributes. It also fails to include unallocated space and deleted files that may contain recoverable evidence, and the copying process updates access times on the source media. This approach does not produce a byte-for-byte duplicate, so it is insufficient for forensic analysis.

  • A full forensic image taken with a write blocker

    Why this is correct

    This is the best answer because a forensic image creates a bit-for-bit copy of the drive while a write blocker prevents accidental changes to the original media. That combination preserves evidentiary integrity and allows the investigator to analyze the copy safely. It is the standard approach when the original disk may later be needed in court or for formal review.

  • A compressed archive of the desktop contents

    Why it's wrong here

    A compressed archive, such as a ZIP or 7-Zip, only collects files visible through the live operating system's file system at the moment it is created. It does not capture unallocated space, file slack, or deleted file remnants, and the compression process itself can alter timestamps and other metadata. Because the archive lacks the disk's full bit-level structure, it cannot serve as a forensic copy or support later recovery of hidden or deleted evidence.

  • The original drive mounted normally on the investigator machine

    Why it's wrong here

    Mounting the original drive in a normal, read-write fashion exposes evidence to unintended modifications from the operating system's journaling, prefetch, and access-time updates, and it can trigger writes to the hibernation or page file. Even a read-only mount may cause subtle changes due to file system mounting routines, and it allows the drive's controller to remap or modify metadata. This alters the original media, breaking the chain of custody and making the evidence inadmissible.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.