CHFI Incident Response and First Responder Skills Practice Question
A first responder arrives at a workstation suspected of being compromised by malware that is still running. The user is logged in and a suspicious process is active. The responder needs to capture volatile data before shutting down. Which command should be used first to capture the contents of RAM to a file?
⚠ Common exam trap
The trap here is assuming that analysis tools like Volatility can acquire memory or that Linux commands work on Windows, when acquisition must be done with a dedicated Windows memory capture utility first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
winpmem.exe -o memory.raw
The order of volatility dictates that RAM contents should be captured before any other action. winpmem is a reliable Windows memory acquisition tool that outputs a raw memory file. The other options are either for a different OS, incorrect syntax, or analysis rather than acquisition. Capturing memory first ensures critical volatile evidence such as running processes and network connections is preserved.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
winpmem.exe -o memory.raw
Why this is correct
winpmem is a Windows memory acquisition tool that captures physical memory to a raw file. Running it first preserves volatile data before any shutdown or further changes. It is specifically designed for forensic imaging of RAM on live Windows systems and is a standard first-responder tool. Capturing memory with winpmem before other actions aligns with order of volatility principles.
- ✗
volatility -f memory.raw imageinfo
Why it's wrong here
Volatility is a memory analysis framework, not an acquisition tool. Running imageinfo requires an existing memory image file; it does not capture RAM. This option confuses analysis with acquisition. The first responder needs to acquire memory first, not analyze an image that does not yet exist.
- ✗
ftk imager --capture-memory
Why it's wrong here
FTK Imager can capture memory on Windows, but the command-line syntax shown is not correct; FTK Imager uses a GUI or specific CLI options like --create-image with memory selection. This option would not execute as written and is not the preferred first action. The scenario requires a reliable, immediate memory capture command.
- ✗
dd if=/dev/mem of=memory.raw
Why it's wrong here
This is a Linux/Unix command that reads from /dev/mem, which is not a valid approach on Windows and is typically restricted even on Linux. It would fail on a Windows workstation and does not provide a reliable memory image. The scenario specifies a Windows system, so this command is inappropriate and would not capture RAM correctly.
Go deeper
Related to this question
Learn chapter
Database Forensics: Investigating Data Breaches
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.