CHFI Computer Forensics Fundamentals and Process Practice Question
A first responder arrives at a crime scene where a computer is turned on. What should the responder do FIRST?
⚠ Common exam trap
EC-Council often tests the misconception that immediate power disconnection is the safest action to prevent data alteration, but the trap is that this destroys volatile evidence and can trigger encryption lockouts, whereas proper documentation and live response preserve the most fragile data first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Photograph the scene and document everything
The first priority at a live crime scene is to preserve the state of the evidence through proper documentation and photography. This ensures an accurate record of the computer's condition, including screen contents, peripheral connections, and environmental context, before any volatile data is lost or altered. The CHFI methodology emphasizes that documentation precedes any seizure or data acquisition steps to maintain chain of custody and evidentiary integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run antivirus software to check for malware
Why it's wrong here
Running antivirus software on a live suspect system is an act that itself alters the evidentiary state: it creates new files, modifies system logs and timestamps, and may auto-quarantine or delete files that are relevant to the case. Even a read-only scan updates data structures like the NTFS $LogFile and last-accessed timestamps, contaminating every piece of digital evidence on the drive. Any malware analysis must be performed on a write-blocked forensic image in a controlled lab environment, never on the original evidence.
- ✗
Immediately disconnect the power cord
Why it's wrong here
Immediately disconnecting the power cord destroys volatile memory, which often holds the most valuable evidence such as running processes, network connections, decrypted sessions, and in-memory credentials. Such a hard power-off also risks filesystem inconsistency, forces a crash-consistency recovery on reboot, and can flush cached writes that overwrite unallocated space. The correct sequence for a live system is to first acquire RAM using a trusted forensic tool, then perform a graceful shutdown or forensically-safe power removal after gathering a memory image.
- ✗
Copy all files from the hard drive
Why it's wrong here
Copying all files from the hard drive merely reproduces the logical directory structure and active files, omitting deleted files, residual data in slack space, unallocated clusters, and the File System Metadata that are essential for recovery and audit. This file-by-file copy also updates each file's last-accessed time and modifies directory entries, further tainting evidence. A forensically sound approach is to create a bit-for-bit HDD image, utilizing a write blocker, so that every sector including free space is captured without altering the source.
- ✓
Photograph the scene and document everything
Why this is correct
Photographing the scene and thoroughly documenting the computer's configuration—including the screen display, attached peripherals, cable connections, power state, and visible indicators—establishes a legally defensible baseline before any forensically relevant action is taken. This initial documentation preserves the original spatial and temporal context of the system, supports the chain of custody, and is indispensable if the scene must be reconstructed or the impact of subsequent steps is questioned. Without such records, even a perfectly performed forensic acquisition may fail admissibility because the examiner cannot prove the scene was preserved.
Go deeper
Related to this question
Learn chapter
Evidence Handling and Chain of Custody
Key term
Volatility Framework
An open-source memory forensics tool used to extract digital evidence from a computer's RAM (random access memory).
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.