SC-200 Respond to security incidents Practice Question
During an incident response, you need to collect forensic evidence from a compromised Azure virtual machine that is currently offline. What is the most efficient method to acquire a disk snapshot for analysis while preserving the integrity of the evidence?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a snapshot of the OS disk from the Azure portal
Exporting a disk via AzCopy is not the most efficient forensic-sound method here because it requires first generating a SAS URL for the disk (e.g., via Grant-AzDiskAccess), which typically means the disk should not be attached to a running VM — the opposite of what this option implies. Even done correctly, going straight to an AzCopy export skips the read-only, platform-level point-in-time snapshot step, so any error or interruption during export risks touching the original disk. Taking a snapshot first (option B) is safer and is the standard first step; the snapshot can subsequently be exported with AzCopy for offline analysis if needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach a new data disk and copy the contents manually
Why it's wrong here
Attaching a new data disk and manually copying file contents is not forensically sound because mounting the OS disk and reading files updates access-time attributes, while the guest OS writes temporary metadata that alters the very timestamps you must rely on as evidence. Manual copying also only captures files visible through the operating system, completely omitting deleted files and unallocated slack space that could contain critical remnants, and it fails to produce a bit-for-bit image of the disk for later verification.
- ✓
Create a snapshot of the OS disk from the Azure portal
Why this is correct
Creating a snapshot of the OS disk from the Azure portal is the correct first step because it produces a read-only, point-in-time copy of the entire virtual disk without powering on the VM, ensuring no writes alter the original evidence. The snapshot captures the raw disk structure including deleted data and file slack, and you can later attach it to a secure analysis VM or use it to instantiate a new disk for offline forensic examination, while storing the snapshot in a separate, access-controlled resource group to maintain chain of custody.
- ✗
Start the VM and use Azure Backup to take a backup
Why it's wrong here
Starting the VM and using Azure Backup to take a backup is unacceptable for forensic evidence because booting the VM mounts the file system, writes event logs, and changes system state, including the very files and timestamps you need to preserve. Azure Backup relies on Volume Shadow Copy and guest-level file backup, which does not produce a raw bit-for-bit disk image and omits unallocated space, and it can trigger application or OS writes that overwrite deleted data still present on the OS disk.
- ✗
Export the disk to a storage account using AzCopy
Why it's wrong here
Exporting the disk via AzCopy requires the VM to be in a running state to access the guest OS for file-level copying, so it cannot operate against an offline VM’s raw disk structure. This option is tempting because AzCopy is a fast tool for transferring large volumes of data to a storage account, and it would be correct for copying log files from a live VM to a central repository.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.