You must be able to order evidence preservation steps correctly, validate a write blocker, and acquire a forensic image without altering the source. The single most important thing is to preserve volatile data first and maintain chain of custody throughout.
Start practicing
Computer Forensics Investigation Process — choose a session length
Free · No account required
Domain overview
This domain covers the forensic investigation process: securing a scene, preserving volatile and non-volatile evidence, maintaining chain of custody, preparing a forensic workstation with write blockers, and acquiring images. Questions present realistic scenarios where you must choose the correct sequence of actions or interpret tool output on Windows and Linux systems.
Exam objectives
Order of volatility and correct evidence collection sequence for Windows and Linux systems
Use of hardware write blockers and validation before imaging USB or hard drives
Forensic imaging commands such as dd, dcfldd, FTK Imager, and EnCase
BitLocker recovery key usage and post-acquisition decryption of encrypted drives
Shutting down or rebooting a system before capturing volatile data, destroying RAM, network connections, and running processes.
Connecting a suspect drive without a verified write blocker, risking accidental modification of evidence.
Misinterpreting e2fsck errors on a Windows system when the tool is meant for Linux ext2/3/4 filesystems.
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a forensic investigation, an analyst discovers that the suspect's hard drive was encrypted using BitLocker. The analyst has obtained the recovery key. Which of the following is the best next step to ensure data integrity?
2A CHFI analyst is called to investigate a suspected data breach. The IT team has already shut down the server. Which of the following is the most appropriate order of actions to preserve evidence?
3An analyst executed the commands shown in the exhibit on a Windows system to prepare a forensic image for analysis. What is the most likely reason for the error message from e2fsck?
4A CHFI analyst is preparing a forensic workstation to image a suspect's USB flash drive. The analyst needs to ensure that the write-blocker is functioning correctly before connecting the drive. Which of the following is the most appropriate method to verify that the write-blocker is preventing write operations?
5A CHFI analyst is called to investigate a suspected insider threat. The suspect's laptop is turned on and logged in. The analyst needs to capture volatile data before shutting it down. Which of the following should the analyst capture first?
You must be able to order evidence preservation steps correctly, validate a write blocker, and acquire a forensic image without altering the source. The single most important thing is to preserve volatile data first and maintain chain of custody throughout.
The Courseiva CHFI question bank contains 5 questions in the Computer Forensics Investigation Process domain, covering the 8% of the exam attributed to this domain in the official EC-Council blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Computer Forensics Investigation Process domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included