Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A first responder arrives at a suspected data breach scene. The system is powered on and a user is logged in. Which of the following actions should the responder take FIRST to preserve volatile data?

⚠ Common exam trap

The EC-Council CHFI exam often tests the misconception that immediate power-off or network disconnection is the safest first step, but the trap is that this destroys volatile data critical for proving the attack timeline and identifying the attacker's tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Collect volatile data such as RAM, network connections, and running processes using appropriate tools.

Volatile data (RAM, network connections, running processes) is lost when power is removed. The first responder must capture this data using tools like FTK Imager, WinPmem, or netstat before any shutdown or disconnection. This aligns with the order of volatility (RFC 3227), which prioritizes memory and network state over disk imaging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Document the scene and take photographs, then proceed to interview witnesses.

    Why it's wrong here

    Documenting the scene and photographing the physical setup is important for establishing context, but it is a non-destructive step that can be performed at any time. The priority at first response is to preserve transient evidence: RAM contents, active network connections, and running processes disappear the moment the system changes state or loses power. Delaying collection to conduct interviews gives those volatile artifacts time to decay, overwrite, or be altered by ongoing system activity.

  • ✗

    Immediately disconnect the network cable and power off the computer.

    Why it's wrong here

    Disconnecting the network cable and immediately powering off the system is the classic 'pull the plug' mistake that destroys the most probative data in a breach investigation. Main memory, encryption keys, open sockets, and process listings are lost on shutdown, and any malware that only exists in RAM is unrecoverable. In addition, sudden power loss can corrupt filesystem metadata or leave full-disk encryption volumes in a locked state, making subsequent forensic imaging difficult or impossible. The correct action is to perform a live acquisition of volatile data first, then perform a controlled shutdown or hibernation if needed.

  • ✓

    Collect volatile data such as RAM, network connections, and running processes using appropriate tools.

    Why this is correct

    This is the correct first step because the order of volatility dictates that data stored in memory and system state is the most short-lived and must be captured before any other activity. Using forensic tools such as a memory acquisition utility (e.g., DumpIt, win32dd, or LiME), netstat for active connections, and ps/tasklist for running processes preserves the live view of the incident. This collection must be performed on the running system, and all tool binaries should be loaded from a trusted read-only medium to avoid altering the very evidence being gathered.

  • ✗

    Use a hardware write-blocker to create a forensic image of the hard drive.

    Why it's wrong here

    Using a hardware write-blocker to image the hard drive is a sound technique for preserving persistent evidence, but it is not the immediate priority at a live breach scene. Hard disk data is non-volatile and will remain intact long after the system is powered down, whereas RAM and network state are ephemeral. Moreover, attaching a write-blocker may require shutting down the system or altering its power state, which would defeat the purpose of volatile data collection. Hard drive imaging should be performed only after the live response phase and after a forensic copy of memory has been secured.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.