easyMultiple Choice
SSCP Practice Question: A company's incident response plan includes a…
A company's incident response plan includes a step to preserve evidence. Which action BEST ensures the integrity of forensic evidence?
⚠ Common exam trap
Watch out — candidates often confuse 'preserving evidence' with 'preserving system availability' or 'quick data capture,' leading them to choose turning off the system or copying files, which actually destroy or alter forensic integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a forensic image with write blocker and hash
Creating a forensic image with a write blocker ensures that the original data is not altered during acquisition, and hashing (e.g., SHA-256) provides a cryptographic integrity check that can later verify the image is an exact bit-for-bit copy. This preserves the chain of custody and admissibility of evidence in legal proceedings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Turn off the system immediately
Why it's wrong here
Shutdown may lose volatile data; preservation requires proper acquisition.
- ✗
Copy files to a network share
Why it's wrong here
Copying files to a network share writes to a mounted file system, changing timestamps and metadata, and provides no write protection or verification. Network copying is tempting because it is quick and centralises data, and would be correct for routine backup or bulk data transfer, not for evidence requiring a documented chain of custody.
- ✗
Run a checksum on the live system
Why it's wrong here
Hashing a live system alters nothing but also captures nothing: the checksum is computed on volatile, changing data, so it cannot later prove the preserved copy is unmodified. Live hashing is tempting because checksums do verify integrity, and would be correct when validating an acquired image or a write-blocked duplicate rather than the running host.
- ✓
Create a forensic image with write blocker and hash
Why this is correct
Creating a forensic image through a write blocker prevents any modification of the original drive, while hashing produces a verifiable value confirming the copy matches the source byte-for-byte. This satisfies the stem's integrity constraint, since any later alteration becomes detectable through hash comparison, preserving evidential value for incident response.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.