Courseiva

SSCP Incident Response and Recovery Practice Question

An incident responder needs to create a forensic image of a suspect hard drive. Which of the following steps is ESSENTIAL to ensure the integrity of the evidence?

⚠ Common exam trap

A common trap in SSCP is the misconception that booting the system or running software-based checks is acceptable. However, any interaction with the original drive that could alter its state—even a read-only mount without a write blocker—can change metadata and break the chain of custody.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a write blocker to prevent modification of the original drive

Using a write blocker is essential because it ensures that no data can be written to the suspect hard drive during the imaging process, preserving the original evidence in a forensically sound state. Without a write blocker, any operating system or imaging tool could inadvertently modify metadata (e.g., access timestamps) or the file system, which would compromise the integrity and admissibility of the evidence in legal proceedings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run an antivirus scan on the drive before imaging

    Why it's wrong here

    An antivirus scan writes to the drive, altering its contents and destroying evidential integrity. A write blocker plus a hash of the original before and after imaging preserves integrity. Scanning belongs to malware analysis on a copy, not the acquisition stage.

  • ✓

    Use a write blocker to prevent modification of the original drive

    Why this is correct

    A hardware write blocker intercepts write commands at the interface level, allowing reads while preventing any modification to the suspect drive. This preserves the original evidence's integrity, ensuring the forensic image is an admissible, verifiable copy.

  • ✗

    Boot the suspect system to verify it is functional

    Why it's wrong here

    Booting the system mounts the filesystem and writes to the disk, modifying timestamps and metadata that the image must capture unchanged. A write blocker and hash verification are essential instead. Booting is useful for live response when volatile memory must be captured before shutdown.

  • ✗

    Perform the imaging over the network to save time

    Why it's wrong here

    Network imaging transfers data through a running OS, which can alter the disk and lacks a hardware write blocker, so the hash may not match the original. Direct write-blocked acquisition is essential. Network imaging suits remote or virtualised systems where physical removal is impractical.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.