Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A first responder arrives at a crime scene where a computer is powered on and displaying a desktop. According to best practices, which of the following actions should the responder take FIRST?

⚠ Common exam trap

The CHFI exam often tests the misconception that preserving volatile data means immediately pulling the plug, when in fact the correct first step is to document the live state without altering it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Photograph the scene and the computer screen.

The first priority at a live crime scene is to document the state of the system before any interaction. Photographing the screen captures volatile data (e.g., open windows, running processes, time) that would be lost upon any keystroke or power change. This aligns with the order of volatility (RFC 3227) and ensures a legally defensible chain of custody from the outset.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Press Ctrl+Alt+Del to check for active user sessions.

    Why it's wrong here

    Pressing Ctrl+Alt+Del invokes the secure attention sequence which can trigger the Windows security dialog, Task Manager, or system event logging, thereby modifying the very volatile state you are trying to preserve. It may also cause a locked screen or screen saver to activate, hiding the on-screen evidence that should be photographed first. Manual keystrokes like this are strictly avoided during initial triage because they can inadvertently launch anti-forensics mechanisms or record user activity, making this an unacceptable method for checking sessions.

  • ✗

    Connect a write blocker and begin imaging the hard drive.

    Why it's wrong here

    Connecting a write blocker and imaging the hard drive is a step that belongs later in the forensic process, after scene documentation, authorization, and a proper order-of-volatility assessment have been completed. Physically connecting hardware can change device state, update timestamps, or interfere with a running system, and a write blocker only protects the storage media—it does nothing to preserve volatile RAM, processes, or network connections that are lost as soon as the machine is powered down. Moreover, an immediate on-scene imaging efort may be premature if a legal warrant or consent is not yet in place, or if the examiner has not first documented the physical layout of the scene.

  • ✗

    Unplug the power cord immediately to preserve volatile data.

    Why it's wrong here

    Unplugging the power cord is detrimental to volatile data preservation because it instantly erases RAM, ongoing network sessions, open file handles, and any encryption keys held in memory. The correct order of volatility requires capturing live system information (e.g., memory dump, running processes, network connections) before powering off, so an immediate power cut violates that principle. Additionally, sudden power loss can cause filesystem corruption, trigger journal replay, or leave encrypted containers in an inconsistent state, potentially destroying the very evidence you are trying to protect.

  • ✓

    Photograph the scene and the computer screen.

    Why this is correct

    Photographing the scene and the computer screen is the first and most critical step because it creates a permanent, objective record of the system's exact state before any interaction occurs. The display may contain incriminating messages, open files, or system logs that are purely volatile and would be lost if the computer is touched, rebooted, or powered down. This documentation, including cable connections and visible media, solidifies the chain of custody and provides the contextual integrity that later forensic analysis depends on, which is why it takes precedence over any hardware or software intervention.

Go deeper

Related to this question

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.