CHFI Computer Forensics Fundamentals and Process Practice Question
A first responder arrives at a scene where a computer is turned on and a user is logged in. What is the FIRST action the responder should take to preserve volatile evidence?
⚠ Common exam trap
EC-Council often tests the order of volatility (RFC 3227) and the misconception that immediate shutdown or hardware removal is safer, when in fact the priority is capturing volatile data first to avoid permanent loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Collect volatile data such as RAM contents and running processes
Volatile data (e.g., RAM contents, running processes, network connections) is lost when power is removed. The first responder must collect this data before any shutdown or hardware removal, following the order of volatility (RFC 3227). This preserves critical evidence that cannot be recovered later.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Photograph the screen and then shut down the system normally
Why it's wrong here
A normal shutdown triggers the operating system's graceful teardown routines: it writes registry hives, flushes cached data to disk, updates file timestamps, and removes temporary files. This systematically destroys transient evidence and overwrites the very user activity trails that forensic examiners need, while also erasing memory-resident malware and network connection state before it can be preserved.
- ✗
Immediately unplug the power cord to prevent data alteration
Why it's wrong here
Physically unplugging the power cord prevents a graceful OS write sequence, but it instantaneously destroys all volatile data in RAM and leaves the filesystem in a dirty state. Journal replay and file-system consistency checks on reboot may alter metadata, and any full-disk encryption keys held only in memory become unrecoverable, making encrypted volumes inaccessible without the passphrase.
- ✗
Remove the hard drive immediately for forensic imaging
Why it's wrong here
Yanking the hard drive out of a running system forfeits the entire volatile layer before it is collected, loses any encryption keys cached in memory, and risks hardware/connector damage or creating a system crash that writes debug data to disk. Even if the drive is later imaged with a write blocker, the missing memory snapshot can make the acquisition legally and technically incomplete, especially for live malware or encrypted volumes.
- ✓
Collect volatile data such as RAM contents and running processes
Why this is correct
Volatile data, by definition, vanishes the instant power is lost, so it must be captured first—RAM contents, running processes, active network connections, open files, and logged-on users. A responder should use statically linked, trusted forensic tools from внешней media to dump memory to a forensically sound image, record output, and preserve the system state in a documented chain of custody before any power-down or disk removal.
Go deeper
Related to this question
Learn chapter
Database Forensics: Investigating Data Breaches
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CHFI
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a forensic investigation, the first responder arrives at a scene where a computer is powered on and a user is logged in. Which of the following is the MOST appropriate initial action?
easy- A.Immediately power off the computer to prevent data alteration
- B.Begin collecting data by copying all files to an external drive
- ✓ C.Disconnect the computer from the network and take a photograph of the screen
- D.Ask the user to save their work and then shut down normally
Why C: Securing the scene and documenting everything is the first priority to preserve evidence and ensure chain of custody. Powering off or accessing the system without proper documentation can lead to evidence spoliation.
Variation 2. Which TWO of the following are considered best practices for a first responder at a digital crime scene? (Select TWO.)
easy- A.Power off the computer immediately to secure data
- B.Boot the system into safe mode to examine logs
- C.Disconnect all cables to isolate the device
- ✓ D.Photograph the scene including screen contents and connections
- ✓ E.Document all actions taken at the scene
Why D: First responders should not power off the system (to preserve volatile data) and should photograph the scene to document the state.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.