CHFI Computer Forensics Fundamentals and Process Practice Question
A first responder arrives at a crime scene where a computer is running. According to standard forensic procedure, what should the responder do FIRST?
⚠ Common exam trap
Many exam-takers confuse the urgency of preserving volatile data with the need to immediately perform a live acquisition or shut down the system, forgetting that scene documentation and security are the foundational first steps in any forensic investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Photograph the scene and secure the area
The first priority at a live crime scene is to preserve the integrity of the scene and all potential evidence. Standard forensic procedure (e.g., from NIST SP 800-86 and ACPO guidelines) mandates that the first responder must photograph the scene to document the state of the computer (including screen contents, cables, and peripherals) and secure the area to prevent unauthorized access or tampering. Only after this documentation and scene stabilization can the responder proceed to handle the live system, such as capturing volatile data or creating a forensic image.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Photograph the scene and secure the area
Why this is correct
Documenting the scene through photographs and establishing a secure perimeter is the mandatory first step in digital forensics, as it creates a verifiable record of the original state of the computer, cables, and peripherals before any interaction. Securing the area prevents unauthorized personnel from touching the machine, which could alter timestamps, memory contents, or other volatile evidence. This step also grounds the chain of custody by showing exactly what was present when first responders arrived, and it should precede any hardware or software actions on the system.
- ✗
Connect a write blocker and create a forensic image immediately
Why it's wrong here
Connecting a write blocker and immediately imaging the hard drive is a critical later step in the forensic workflow, but performing it before documenting the scene violates standard operating procedure because it modifies the system state by requiring the computer to be powered and potentially mounting devices. It also risks missing volatile data residing in RAM, such as encryption keys or active network connections, that would be lost when powering on or off. Additionally, a first responder may lack the required forensic tools, legal authority, or trained expertise to perform a sound acquisition, so scene documentation and triage must come first.
- ✗
Immediately shut down the computer to prevent data alteration
Why it's wrong here
Immediately shutting down the computer to preserve evidence is a common but flawed instinct because normal shutdown triggers the operating system to modify system files, such as clearing page files and recording clean shutdown events, and it destroys all volatile data in memory. Furthermore, modern systems with Fast Startup may not fully shut down and can flush cached data to disk, altering evidence. The correct sequence is to photograph the scene, then capture the RAM contents using a specialized memory acquisition tool, and finally choose the appropriate shutdown method based on the incident type.
- ✗
Pull the power cord to ensure the system does not shut down normally
Why it's wrong here
Pulling the power cord is a controlled, but not universally safe, action that should only be taken after volatile memory has been captured and the need to bypass the operating system's shutdown routines is justified, because an abrupt power loss can leave NTFS or ext4 filesystems inconsistent and may trigger journal replay or checkdisk on reboot. On systems with self-encrypting drives, cutting power can strip the decryption key from memory and make the drive inaccessible, while RAID arrays might enter a degraded state. This step is never the first action when a system is running, and it is only one choice among several based on the platform and evidence goals.
Go deeper
Related to this question
Learn chapter
Reporting, Documentation, and Expert Testimony
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.