Courseiva

CHFI Incident Response and First Responder Skills Practice Question

A first responder is called to a scene where a Windows laptop is suspected of being used in a crime. The laptop is turned on and logged in. The responder needs to preserve the most volatile evidence first. Which of the following should be captured first?

⚠ Common exam trap

The trap here is assuming that disk-based artifacts like the registry or event logs are more volatile than RAM, when actually RAM is lost immediately upon power-off.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The contents of RAM

The order of volatility dictates that RAM is the most volatile and should be captured first. Registry, pagefile, and event logs are stored on disk and persist after shutdown, making them less volatile. Capturing RAM first ensures that running processes, network connections, and potentially encryption keys are preserved before any other action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The contents of RAM

    Why this is correct

    RAM contains the most volatile data, including running processes, network connections, and encryption keys. It is lost when the system is powered off. Capturing RAM first aligns with the order of volatility and ensures critical evidence is preserved. This is a fundamental first-responder principle for live systems.

  • ✗

    The event logs

    Why it's wrong here

    Event logs are stored on disk and are non-volatile. They are important for reconstructing events but are not lost on shutdown. They should be collected after volatile data like RAM. The question emphasizes the most volatile evidence, which is not event logs.

  • ✗

    The Windows Registry

    Why it's wrong here

    The Windows Registry is stored on disk and is non-volatile. While important for forensic analysis, it persists after shutdown and is not the most volatile evidence. Capturing RAM first is necessary because registry data will remain available later. The question asks for the most volatile evidence, which is not the registry.

  • ✗

    The pagefile.sys file

    Why it's wrong here

    Pagefile.sys is a disk-based file used for virtual memory. Although it can contain remnants of memory, it is not as volatile as RAM and may persist across reboots. It is considered non-volatile and should be collected after RAM. The most volatile data is in active memory, not the pagefile.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.