CHFI Computer Forensics Fundamentals and Process Practice Question
A first responder arrives at a crime scene where a computer is running. Which THREE actions should the first responder take to preserve volatile evidence?
⚠ Common exam trap
EC-Council often tests the misconception that immediately cutting power is the safest action, but the trap is that this destroys the most volatile evidence (RAM) and can corrupt the filesystem, whereas a proper forensic response prioritizes capturing memory first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Collect contents of RAM using a tool like FTK Imager or dd
Option A is correct because RAM contents are highly volatile and lost on power-off, so capturing memory with a tool like FTK Imager or dd preserves running processes, encryption keys, and other in-memory artifacts. Option C is correct because netstat records active network connections and listening ports, which are volatile and can reveal remote sessions or exfiltration activity before they disappear. Option E is correct because photographing the screen captures the current visual state of the running system, including open windows and displayed data, without altering the machine. Option B is not appropriate because unplugging the power cord immediately destroys volatile evidence such as RAM and active connections. Option D is not appropriate because running an antivirus scan modifies the system, overwrites volatile data, and can destroy evidence rather than preserve it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Collect contents of RAM using a tool like FTK Imager or dd
Why this is correct
Collecting RAM with FTK Imager or dd is correct because memory holds volatile, ephemeral data—encryption keys, plaintext credentials, running processes, injected code, and evidence of malware that never touches disk. FTK Imager can create a forensic memory dump while dd, if used with a memory-specific driver, also works; both must be executed carefully to avoid altering the state they are capturing. This action preserves the single most fragile category of evidence before it disappears the moment the system loses power or reboots.
- ✗
Unplug the power cord immediately
Why it's wrong here
Unplugging the power cord is wrong because an immediate hard power-off instantly terminates every process and flushes the contents of RAM, erasing open files, network connections, encryption keys, and any unsaved data that might be crucial evidence. It also prevents a clean shutdown procedure that could have triggered anti-forensic routines, but the greater loss is the total destruction of the volatile memory layer. The system's disk may be preserved, but the live state — the most evidentially time-sensitive component — is permanently gone.
- ✓
Record active network connections using netstat
Why this is correct
Recording active network connections with netstat is correct because network state is highly volatile; an active session to a command-and-control server or an ongoing exfiltration may vanish within seconds. Using netstat -an (or with -o to include process IDs) reveals remote IP addresses, ports, TCP state, and the owning process, which can tie suspicious network activity to a specific executable. Capturing this before any other action provides a snapshot of the system's live communication that is unobtainable after shutdown or disconnection.
- ✗
Run a full antivirus scan on the system
Why it's wrong here
Running a full antivirus scan is wrong because the scan itself is a write-intensive operation that modifies system state — it updates access times, creates quarantine files, writes log entries, and may alter files that are themselves evidence. Additionally, the scan can trigger malware behavior or cause the AV to delete or encrypt suspicious files, destroying the very artifacts a forensic examiner would want to analyze. This violates the cardinal rule of not changing the scene; any analysis or scanning belongs on a forensic copy, never on the live original.
- ✓
Photograph the screen to capture current state
Why this is correct
Photographing the screen is correct because it is a completely non-invasive method of preserving the volatile visual state of the system before any interaction. The photograph captures open windows, running applications, error dialogs, clock time, and possibly even on-screen messages that indicate ongoing activity — all of which would be lost upon shutdown or if the investigator touches the keyboard. Unlike a digital screenshot, which requires software modifications, a physical photo documents the state without altering the evidence.
Go deeper
Related to this question
Learn chapter
Database Forensics: Investigating Data Breaches
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.