Courseiva

SSCP Incident Response and Recovery Practice Question

A security team is collecting evidence from a compromised server. They need to create a forensic image. Which of the following is the CORRECT procedure to ensure data integrity?

⚠ Common exam trap

A common mix-up: candidates think a simple backup or file copy is sufficient for forensic evidence, but the SSCP exam emphasizes that only a write-blocked bit-for-bit copy with hash verification ensures data integrity and admissibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a write blocker to create a bit-for-bit copy, then compute MD5 hash of the original and the copy to verify they match

Forensic imaging requires a write blocker to prevent any modification to the original evidence, and a bit-for-bit copy preserves all data, including slack space and deleted files. Computing an MD5 hash of both the original and the copy verifies integrity by ensuring the hashes match, confirming no data alteration occurred during acquisition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a write blocker to create a bit-for-bit copy, then compute MD5 hash of the original and the copy to verify they match

    Why this is correct

    A write blocker prevents any modification to the source drive during imaging, preserving evidential integrity. Hashing both the original and the bit-for-bit copy with MD5 confirms they are identical, satisfying the requirement to verify integrity.

  • ✗

    Take a photo of the screen and document file timestamps manually

    Why it's wrong here

    Photographing the screen captures no bit-level data and cannot be hashed, so no verifiable forensic image is produced. It tempts because documenting the scene and recording timestamps is genuine evidence-handling practise, and that is the correct activity for chain-of-custody records rather than imaging.

  • ✗

    Create a compressed image file using software without a write blocker

    Why it's wrong here

    Without a write blocker, the acquisition host can write to the source drive, modifying metadata and invalidating the image's hash. It tempts because compression is standard for storing large images efficiently, and that is legitimate once a verified, write-blocked image already exists.

  • ✗

    Boot the system and run a backup utility to copy files to an external drive

    Why it's wrong here

    Booting the system alters file timestamps and mounted volumes, destroying volatile evidence and integrity, so the image cannot be verified against the original. It tempts because backup utilities are the normal way to copy data for recovery, and that is exactly the scenario where this approach would be acceptable.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.