Courseiva

CHFI Incident Response and First Responder Skills Practice Question

A first responder arrives at a workstation suspected of being compromised by malware that is still running. The user is logged in and a suspicious process is active. The responder needs to capture volatile data before shutting down. Which command should be used first to capture the contents of RAM to a file?

⚠ Common exam trap

The trap here is assuming that analysis tools like Volatility can acquire memory or that Linux commands work on Windows, when acquisition must be done with a dedicated Windows memory capture utility first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

winpmem.exe -o memory.raw

The order of volatility dictates that RAM contents should be captured before any other action. winpmem is a reliable Windows memory acquisition tool that outputs a raw memory file. The other options are either for a different OS, incorrect syntax, or analysis rather than acquisition. Capturing memory first ensures critical volatile evidence such as running processes and network connections is preserved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    winpmem.exe -o memory.raw

    Why this is correct

    winpmem is a Windows memory acquisition tool that captures physical memory to a raw file. Running it first preserves volatile data before any shutdown or further changes. It is specifically designed for forensic imaging of RAM on live Windows systems and is a standard first-responder tool. Capturing memory with winpmem before other actions aligns with order of volatility principles.

  • ✗

    volatility -f memory.raw imageinfo

    Why it's wrong here

    Volatility is a memory analysis framework, not an acquisition tool. Running imageinfo requires an existing memory image file; it does not capture RAM. This option confuses analysis with acquisition. The first responder needs to acquire memory first, not analyze an image that does not yet exist.

  • ✗

    ftk imager --capture-memory

    Why it's wrong here

    FTK Imager can capture memory on Windows, but the command-line syntax shown is not correct; FTK Imager uses a GUI or specific CLI options like --create-image with memory selection. This option would not execute as written and is not the preferred first action. The scenario requires a reliable, immediate memory capture command.

  • ✗

    dd if=/dev/mem of=memory.raw

    Why it's wrong here

    This is a Linux/Unix command that reads from /dev/mem, which is not a valid approach on Windows and is typically restricted even on Linux. It would fail on a Windows workstation and does not provide a reliable memory image. The scenario specifies a Windows system, so this command is inappropriate and would not capture RAM correctly.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.