CHFI Computer Forensics Fundamentals and Process Practice Question
A first responder arrives at a suspected data breach scene. The system is powered on and a user is logged in. Which of the following actions should the responder take FIRST to preserve volatile data?
⚠ Common exam trap
The EC-Council CHFI exam often tests the misconception that immediate power-off or network disconnection is the safest first step, but the trap is that this destroys volatile data critical for proving the attack timeline and identifying the attacker's tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Collect volatile data such as RAM, network connections, and running processes using appropriate tools.
Volatile data (RAM, network connections, running processes) is lost when power is removed. The first responder must capture this data using tools like FTK Imager, WinPmem, or netstat before any shutdown or disconnection. This aligns with the order of volatility (RFC 3227), which prioritizes memory and network state over disk imaging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Document the scene and take photographs, then proceed to interview witnesses.
Why it's wrong here
Documenting the scene and photographing the physical setup is important for establishing context, but it is a non-destructive step that can be performed at any time. The priority at first response is to preserve transient evidence: RAM contents, active network connections, and running processes disappear the moment the system changes state or loses power. Delaying collection to conduct interviews gives those volatile artifacts time to decay, overwrite, or be altered by ongoing system activity.
- ✗
Immediately disconnect the network cable and power off the computer.
Why it's wrong here
Disconnecting the network cable and immediately powering off the system is the classic 'pull the plug' mistake that destroys the most probative data in a breach investigation. Main memory, encryption keys, open sockets, and process listings are lost on shutdown, and any malware that only exists in RAM is unrecoverable. In addition, sudden power loss can corrupt filesystem metadata or leave full-disk encryption volumes in a locked state, making subsequent forensic imaging difficult or impossible. The correct action is to perform a live acquisition of volatile data first, then perform a controlled shutdown or hibernation if needed.
- ✓
Collect volatile data such as RAM, network connections, and running processes using appropriate tools.
Why this is correct
This is the correct first step because the order of volatility dictates that data stored in memory and system state is the most short-lived and must be captured before any other activity. Using forensic tools such as a memory acquisition utility (e.g., DumpIt, win32dd, or LiME), netstat for active connections, and ps/tasklist for running processes preserves the live view of the incident. This collection must be performed on the running system, and all tool binaries should be loaded from a trusted read-only medium to avoid altering the very evidence being gathered.
- ✗
Use a hardware write-blocker to create a forensic image of the hard drive.
Why it's wrong here
Using a hardware write-blocker to image the hard drive is a sound technique for preserving persistent evidence, but it is not the immediate priority at a live breach scene. Hard disk data is non-volatile and will remain intact long after the system is powered down, whereas RAM and network state are ephemeral. Moreover, attaching a write-blocker may require shutting down the system or altering its power state, which would defeat the purpose of volatile data collection. Hard drive imaging should be performed only after the live response phase and after a forensic copy of memory has been secured.
Go deeper
Related to this question
Learn chapter
Forensic Tools and Laboratory Setup
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.