Courseiva
mediumMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: During a forensic investigation, it is crucial to…

During a forensic investigation, it is crucial to preserve the original evidence. What is the first step the investigator should take when acquiring a hard drive?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a forensic image using a write blocker

Creating a bit-for-bit forensic image using a write blocker preserves the original evidence. Option D (calculate the hash) is done after imaging to verify integrity. Option A (booting the drive) would modify data and compromise the evidence. Option B (turning off the computer and removing the hard drive) may be necessary but is not the first step in acquisition; the first step is to create a forensic image with a write blocker.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Boot the drive to check for operating system errors

    Why it's wrong here

    Booting modifies the drive, compromising evidence.

  • Turn off the computer and remove the hard drive

    Why it's wrong here

    Removing the drive is a step, but the first step in acquisition is to image it with a write blocker.

  • Create a forensic image using a write blocker

    Why this is correct

    A write-blocked forensic image ensures no data is altered during acquisition.

  • Calculate the hash of the original drive

    Why it's wrong here

    Hashing should be performed after imaging to verify integrity, but not as the first step.

About these practice questions

This CC question is part of Courseiva's 976-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.