Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A first responder arrives at a crime scene where a computer is turned on. What should the responder do FIRST?

⚠ Common exam trap

EC-Council often tests the misconception that immediate power disconnection is the safest action to prevent data alteration, but the trap is that this destroys volatile evidence and can trigger encryption lockouts, whereas proper documentation and live response preserve the most fragile data first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Photograph the scene and document everything

The first priority at a live crime scene is to preserve the state of the evidence through proper documentation and photography. This ensures an accurate record of the computer's condition, including screen contents, peripheral connections, and environmental context, before any volatile data is lost or altered. The CHFI methodology emphasizes that documentation precedes any seizure or data acquisition steps to maintain chain of custody and evidentiary integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run antivirus software to check for malware

    Why it's wrong here

    Running antivirus software on a live suspect system is an act that itself alters the evidentiary state: it creates new files, modifies system logs and timestamps, and may auto-quarantine or delete files that are relevant to the case. Even a read-only scan updates data structures like the NTFS $LogFile and last-accessed timestamps, contaminating every piece of digital evidence on the drive. Any malware analysis must be performed on a write-blocked forensic image in a controlled lab environment, never on the original evidence.

  • ✗

    Immediately disconnect the power cord

    Why it's wrong here

    Immediately disconnecting the power cord destroys volatile memory, which often holds the most valuable evidence such as running processes, network connections, decrypted sessions, and in-memory credentials. Such a hard power-off also risks filesystem inconsistency, forces a crash-consistency recovery on reboot, and can flush cached writes that overwrite unallocated space. The correct sequence for a live system is to first acquire RAM using a trusted forensic tool, then perform a graceful shutdown or forensically-safe power removal after gathering a memory image.

  • ✗

    Copy all files from the hard drive

    Why it's wrong here

    Copying all files from the hard drive merely reproduces the logical directory structure and active files, omitting deleted files, residual data in slack space, unallocated clusters, and the File System Metadata that are essential for recovery and audit. This file-by-file copy also updates each file's last-accessed time and modifies directory entries, further tainting evidence. A forensically sound approach is to create a bit-for-bit HDD image, utilizing a write blocker, so that every sector including free space is captured without altering the source.

  • ✓

    Photograph the scene and document everything

    Why this is correct

    Photographing the scene and thoroughly documenting the computer's configuration—including the screen display, attached peripherals, cable connections, power state, and visible indicators—establishes a legally defensible baseline before any forensically relevant action is taken. This initial documentation preserves the original spatial and temporal context of the system, supports the chain of custody, and is indispensable if the scene must be reconstructed or the impact of subsequent steps is questioned. Without such records, even a perfectly performed forensic acquisition may fail admissibility because the examiner cannot prove the scene was preserved.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.