CHFI Computer Forensics Investigation Process Practice Question
A CHFI analyst is called to investigate a suspected data breach. The IT team has already shut down the server. Which of the following is the most appropriate order of actions to preserve evidence?
⚠ Common exam trap
EC-Council often tests the misconception that immediate data collection (like powering on or scanning) is acceptable, when in fact the first priority is to preserve the scene and prevent any modification to the evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure the scene, photograph the setup, document connections, remove hard drives, and create forensic images using a write-blocker.
It follows the established forensic investigation process: secure the scene to prevent contamination, document the state of the server (photographs and connection diagrams), then physically remove the hard drives and create forensic images using a write-blocker to preserve the original data without alteration. This ensures evidence integrity and admissibility in legal proceedings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately power on the server to check for running processes.
Why it's wrong here
Powering on the server to inspect running processes is improper because it alters volatile evidence and writes to the disk. Booting the system updates file access timestamps, modifies registry keys, creates or rotates logs, and swaps data into the pagefile, thereby contaminating the media. Additionally, process information is lost unless a live response toolkit is used with proper volatile data collection procedures before shutdown. The correct approach is to preserve and acquire evidence without executing the operating system.
- ✗
Copy all files from the server to an external USB drive.
Why it's wrong here
Copying all files to an external USB drive produces a logical extraction that fails to capture deleted data, residual data in unallocated space, slack space, or hidden partitions. It also does not preserve critical metadata such as file system timestamps and MAC times, and may alter access times during the copy operation. A forensic image is a bit-for-bit duplicate with hash verification, which is required to prove integrity and to recover artifacts that a file copy would omit.
- ✗
Run antivirus scan to ensure no malware is present before imaging.
Why it's wrong here
Running an antivirus scan before imaging is an invasive action that can modify the evidence itself. The scanner will read numerous files, updating their last-accessed timestamps, and may write quarantine records, log files, or virus definitions to the target disk. Some AV engines also unpack or decrypt suspect files, changing their content on disk. To preserve the original state, an image must be created first, and then malware analysis can be performed on the copy.
- ✓
Secure the scene, photograph the setup, document connections, remove hard drives, and create forensic images using a write-blocker.
Why this is correct
This is the correct forensic process: first secure the scene to prevent interference, then photograph and document the physical setup and all connections to preserve the context. Identify and collect volatile data if applicable, then remove the hard drives using proper anti-static procedures. Using a write-blocker when creating a forensic image prevents any write operations to the original drive, and hashing the image ensures the preservation of a verifiable, bit-for-bit copy for analysis and chain-of-custody.
Go deeper
Related to this question
Learn chapter
Forensic Tools and Laboratory Setup
Key term
Autopsy Tool
An open-source digital forensics platform used to analyze hard drives, recover deleted files, and uncover evidence from computers and storage media.
Key term
Volatility Framework
An open-source memory forensics tool used to extract digital evidence from a computer's RAM (random access memory).
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.