Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A first responder arrives at a scene where a computer is turned on and a user is logged in. What is the FIRST action the responder should take to preserve volatile evidence?

⚠ Common exam trap

EC-Council often tests the order of volatility (RFC 3227) and the misconception that immediate shutdown or hardware removal is safer, when in fact the priority is capturing volatile data first to avoid permanent loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Collect volatile data such as RAM contents and running processes

Volatile data (e.g., RAM contents, running processes, network connections) is lost when power is removed. The first responder must collect this data before any shutdown or hardware removal, following the order of volatility (RFC 3227). This preserves critical evidence that cannot be recovered later.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Photograph the screen and then shut down the system normally

    Why it's wrong here

    A normal shutdown triggers the operating system's graceful teardown routines: it writes registry hives, flushes cached data to disk, updates file timestamps, and removes temporary files. This systematically destroys transient evidence and overwrites the very user activity trails that forensic examiners need, while also erasing memory-resident malware and network connection state before it can be preserved.

  • ✗

    Immediately unplug the power cord to prevent data alteration

    Why it's wrong here

    Physically unplugging the power cord prevents a graceful OS write sequence, but it instantaneously destroys all volatile data in RAM and leaves the filesystem in a dirty state. Journal replay and file-system consistency checks on reboot may alter metadata, and any full-disk encryption keys held only in memory become unrecoverable, making encrypted volumes inaccessible without the passphrase.

  • ✗

    Remove the hard drive immediately for forensic imaging

    Why it's wrong here

    Yanking the hard drive out of a running system forfeits the entire volatile layer before it is collected, loses any encryption keys cached in memory, and risks hardware/connector damage or creating a system crash that writes debug data to disk. Even if the drive is later imaged with a write blocker, the missing memory snapshot can make the acquisition legally and technically incomplete, especially for live malware or encrypted volumes.

  • ✓

    Collect volatile data such as RAM contents and running processes

    Why this is correct

    Volatile data, by definition, vanishes the instant power is lost, so it must be captured first—RAM contents, running processes, active network connections, open files, and logged-on users. A responder should use statically linked, trusted forensic tools from внешней media to dump memory to a forensically sound image, record output, and preserve the system state in a documented chain of custody before any power-down or disk removal.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a forensic investigation, the first responder arrives at a scene where a computer is powered on and a user is logged in. Which of the following is the MOST appropriate initial action?

easy
  • A.Immediately power off the computer to prevent data alteration
  • B.Begin collecting data by copying all files to an external drive
  • ✓ C.Disconnect the computer from the network and take a photograph of the screen
  • D.Ask the user to save their work and then shut down normally

Why C: Securing the scene and documenting everything is the first priority to preserve evidence and ensure chain of custody. Powering off or accessing the system without proper documentation can lead to evidence spoliation.

Variation 2. Which TWO of the following are considered best practices for a first responder at a digital crime scene? (Select TWO.)

easy
  • A.Power off the computer immediately to secure data
  • B.Boot the system into safe mode to examine logs
  • C.Disconnect all cables to isolate the device
  • ✓ D.Photograph the scene including screen contents and connections
  • ✓ E.Document all actions taken at the scene

Why D: First responders should not power off the system (to preserve volatile data) and should photograph the scene to document the state.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.