20+ practice questions focused on Evidence Acquisition and Duplication — one of the most tested topics on the Computer Hacking Forensic Investigator CHFI exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Evidence Acquisition and Duplication PracticeDuring a forensic investigation, you are asked to acquire the contents of RAM from a live Windows 10 system without causing system instability. Which tool would be most appropriate for this task?
Explanation: Belkasoft RAM Capturer is the most appropriate tool for acquiring RAM from a live Windows 10 system because it is designed specifically for live memory acquisition on Windows, uses a lightweight kernel-mode driver to read physical memory without causing system instability, and supports acquisition from 64-bit systems. Unlike other tools, it minimizes interaction with the target process list and avoids loading unnecessary user-mode components that could trigger crashes or alter the memory state.
During a network forensic investigation, you need to capture live network traffic from a switch span port. Which tool would best capture the traffic in a forensically sound manner?
Explanation: Wireshark is the best tool for capturing live network traffic from a switch SPAN port in a forensically sound manner because it provides a robust graphical interface for real-time packet capture and analysis, supports full packet capture with timestamps, and can write captures directly to a pcapng file format that preserves packet integrity and metadata. Its ability to run in promiscuous mode ensures all traffic from the SPAN port is captured without altering the data, meeting forensic requirements for accuracy and completeness.
You are acquiring a laptop with a self-encrypting drive (SED) that is powered on and logged in. What is the best method to acquire the drive while preserving encrypted data?
Explanation: When a self-encrypting drive (SED) is powered on and logged in, the drive's hardware encryption key is already loaded and the data is accessible through the operating system. The best method to preserve the encrypted data in its decrypted state is to acquire a logical image from the running OS, which captures files and metadata without powering off the drive and losing the decryption context. Removing power or rebooting would cause the SED to lock, requiring the authentication key again and potentially altering the data state.
Which TWO of the following are valid methods for acquiring volatile data from a live Windows system? (Choose two.)
Explanation: Capturing active network connections (e.g., using `netstat -anob` or `netstat -ano`) retrieves volatile data that is lost when the system is powered off. This data includes current TCP/UDP connections, listening ports, and associated process IDs, which are critical for identifying active network threats or unauthorized communications during incident response.
Which THREE of the following are acceptable best practices when acquiring evidence from a mobile device? (Choose three.)
Explanation: Documenting the SIM card information, such as the ICCID (Integrated Circuit Card Identifier) and IMSI (International Mobile Subscriber Identity), is a critical step in establishing chain of custody and preserving evidence that may link the device to a specific subscriber or network. This documentation must occur before any acquisition to ensure the SIM's data is not altered by subsequent imaging or isolation procedures.
+15 more Evidence Acquisition and Duplication questions available
Practice all Evidence Acquisition and Duplication questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Evidence Acquisition and Duplication. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Evidence Acquisition and Duplication questions on the CHFI frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Evidence Acquisition and Duplication is tested as part of the Computer Hacking Forensic Investigator CHFI blueprint. Practicing with targeted Evidence Acquisition and Duplication questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CHFI practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Evidence Acquisition and Duplication is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Evidence Acquisition and Duplication practice session with instant scoring and detailed explanations.
Start Evidence Acquisition and Duplication Practice →