19+ practice questions focused on Computer Forensics Lab — one of the most tested topics on the Computer Hacking Forensic Investigator CHFI exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Computer Forensics Lab PracticeDuring a forensic investigation, an analyst needs to acquire data from a live Windows system without altering the system's state. Which tool should the analyst use to capture the contents of RAM?
Explanation: FTK Imager Lite is designed for live forensic acquisition on Windows systems, including capturing RAM contents without altering the system state. It uses a lightweight, read-only approach that avoids writing to the disk or modifying memory pages, preserving the integrity of the evidence.
A forensic analyst is troubleshooting a write-blocker that is not working correctly. The analyst connected the write-blocker between the suspect drive and the forensic workstation, but the workstation still shows the drive as writable. What is the most likely cause?
Explanation: When a write-blocker is powered on after the suspect drive is already connected, the drive may have already been enumerated by the operating system as a writable device. Write-blockers rely on intercepting and filtering ATA/SCSI commands at the hardware level before the OS sees the drive; if the drive is connected first, the OS may have already sent write commands or cached write attributes, bypassing the blocker's protection. This is why the proper sequence is to power on the write-blocker first, then connect the suspect drive.
Which THREE of the following are recommended practices for maintaining the integrity of digital evidence in a forensics lab?
Explanation: Maintaining a detailed chain of custody log (Option A) is a recommended practice because it provides a verifiable, chronological record of every person who handled the evidence, the time and date of each transfer, and the purpose of each transfer. This ensures the evidence's integrity by demonstrating that it has not been tampered with or altered from the moment of seizure through analysis and presentation in court. Without a proper chain of custody, the evidence can be challenged as inadmissible under rules like Federal Rule of Evidence 901.
You are a forensic analyst in a corporate lab. A compromised server was taken offline and brought to the lab. The server runs Windows Server 2019 with a RAID 5 array of three 1TB SATA drives. The drives are hot-swappable. The server was shut down properly before removal. The lab has a forensic workstation with write-blockers, a hardware RAID controller, and imaging software. The analyst needs to acquire a forensic image of the RAID array. What is the correct course of action?
Explanation: The RAID 5 array must be reconstructed using the same controller model (or an identical one) to correctly interpret the parity and striping metadata. Imaging the logical volume via a write-blocker preserves the integrity of the file system and ensures a forensically sound acquisition of the live data, which is the standard practice when the controller is available and the array is intact.
Refer to the exhibit. A forensic examiner is analyzing a Windows system and sees the above NTFS file metadata. The user claims the file was last accessed at 09:15. Which of the following best explains the discrepancy?
Explanation: The $UsnJrnl (Update Sequence Number Journal) records that the file was modified, and on Windows systems, when a file is opened for reading, the last access time is updated by default. The discrepancy arises because the user claims the file was last accessed at 09:15, but the NTFS metadata shows a different last access time, which could be due to the system updating the last access time upon modification or read operations, as recorded in the $UsnJrnl.
+14 more Computer Forensics Lab questions available
Practice all Computer Forensics Lab questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Computer Forensics Lab. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Computer Forensics Lab questions on the CHFI frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Computer Forensics Lab is tested as part of the Computer Hacking Forensic Investigator CHFI blueprint. Practicing with targeted Computer Forensics Lab questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CHFI practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Computer Forensics Lab is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Computer Forensics Lab practice session with instant scoring and detailed explanations.
Start Computer Forensics Lab Practice →