CHFI Computer Forensics Fundamentals and Process Practice Question
A first responder arrives at a crime scene where a computer is powered on and displaying a desktop. According to best practices, which of the following actions should the responder take FIRST?
⚠ Common exam trap
The CHFI exam often tests the misconception that preserving volatile data means immediately pulling the plug, when in fact the correct first step is to document the live state without altering it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Photograph the scene and the computer screen.
The first priority at a live crime scene is to document the state of the system before any interaction. Photographing the screen captures volatile data (e.g., open windows, running processes, time) that would be lost upon any keystroke or power change. This aligns with the order of volatility (RFC 3227) and ensures a legally defensible chain of custody from the outset.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Press Ctrl+Alt+Del to check for active user sessions.
Why it's wrong here
Pressing Ctrl+Alt+Del invokes the secure attention sequence which can trigger the Windows security dialog, Task Manager, or system event logging, thereby modifying the very volatile state you are trying to preserve. It may also cause a locked screen or screen saver to activate, hiding the on-screen evidence that should be photographed first. Manual keystrokes like this are strictly avoided during initial triage because they can inadvertently launch anti-forensics mechanisms or record user activity, making this an unacceptable method for checking sessions.
- ✗
Connect a write blocker and begin imaging the hard drive.
Why it's wrong here
Connecting a write blocker and imaging the hard drive is a step that belongs later in the forensic process, after scene documentation, authorization, and a proper order-of-volatility assessment have been completed. Physically connecting hardware can change device state, update timestamps, or interfere with a running system, and a write blocker only protects the storage media—it does nothing to preserve volatile RAM, processes, or network connections that are lost as soon as the machine is powered down. Moreover, an immediate on-scene imaging efort may be premature if a legal warrant or consent is not yet in place, or if the examiner has not first documented the physical layout of the scene.
- ✗
Unplug the power cord immediately to preserve volatile data.
Why it's wrong here
Unplugging the power cord is detrimental to volatile data preservation because it instantly erases RAM, ongoing network sessions, open file handles, and any encryption keys held in memory. The correct order of volatility requires capturing live system information (e.g., memory dump, running processes, network connections) before powering off, so an immediate power cut violates that principle. Additionally, sudden power loss can cause filesystem corruption, trigger journal replay, or leave encrypted containers in an inconsistent state, potentially destroying the very evidence you are trying to protect.
- ✓
Photograph the scene and the computer screen.
Why this is correct
Photographing the scene and the computer screen is the first and most critical step because it creates a permanent, objective record of the system's exact state before any interaction occurs. The display may contain incriminating messages, open files, or system logs that are purely volatile and would be lost if the computer is touched, rebooted, or powered down. This documentation, including cable connections and visible media, solidifies the chain of custody and provides the contextual integrity that later forensic analysis depends on, which is why it takes precedence over any hardware or software intervention.
Go deeper
Related to this question
Learn chapter
Data Acquisition and Duplication Techniques
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.