SY0-701 Security Operations Practice Question
Security receives a company laptop used in an insider theft investigation. A manager wants the device moved to another office for review by legal staff. Which action best supports chain of custody?
⚠ Common exam trap
CompTIA often tests the misconception that simply securing the device or performing preliminary analysis is sufficient, but the trap here is that any action altering the device state or lacking formal documentation breaks the chain of custody, even if the intent is to preserve evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place it in a labeled evidence bag, record the collector, time, location, and condition, and require signatures for each transfer.
It follows the formal chain of custody process required for evidence handling. Placing the laptop in a labeled evidence bag with documented collector, time, location, and condition, along with requiring signatures for each transfer, ensures the integrity and admissibility of evidence by creating an unbroken audit trail. This aligns with NIST SP 800-86 and forensic best practices for maintaining custody of digital evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Power on the laptop to confirm the user profile and recent activity before transport.
Why it's wrong here
Booting the laptop alters the system state by updating file access timestamps, registry keys, and log files, and it may trigger encryption or remote-wipe commands. This contamination creates new artifacts that cannot be distinguished from original evidence, potentially invalidating forensic analysis. The device must be preserved as-is, and any power-on attempt should be performed later by a forensic examiner using a write blocker.
- ✓
Place it in a labeled evidence bag, record the collector, time, location, and condition, and require signatures for each transfer.
Why this is correct
Chain of custody depends on proving who handled the evidence, when, where, and in what condition. Documenting the device at collection, sealing it appropriately, and recording every transfer creates a defensible record that supports legal review. This approach reduces the risk of tampering claims and helps establish that the laptop was preserved from the moment it was seized until it reaches legal or forensic personnel.
- ✗
Remove the drive and clone it without documenting the collection process.
Why it's wrong here
Creating a forensic clone of the drive is a valid preservation step, but performing it without documenting the collector, time, location, condition, and every transfer breaks the chain of custody. Without a verifiable record, the clone and the original device cannot be linked, and the evidence is vulnerable to claims of substitution or tampering. A properly documented acquisition using a write blocker and hash verification is only admissible if the custody trail is complete from the moment of seizure.
- ✗
Email a photo of the laptop to legal and leave the original on a desk.
Why it's wrong here
Photographing the laptop captures only its external appearance and does not preserve the storage media or volatile data, leaving the actual evidence unprotected. Leaving the original unsecured on a desk permits unauthorized access, accidental damage, or intentional tampering, destroying the evidence's integrity and authenticity. A photo is supplementary documentation, not a substitute for physically securing the device in a labeled evidence bag with a tamper-evident seal.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Evidence handling
Evidence handling is the process of properly collecting, preserving, documenting, and storing digital evidence to maintain its integrity and admissibility in legal or administrative proceedings.
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.