Courseiva
Incident Response and First Responder SkillseasyMultiple ChoiceObjective-mapped

CHFI Incident Response and First Responder Skills Practice Question

A first responder is called to investigate a potential insider threat. The suspect's computer is turned off. What is the BEST procedure?

⚠ Common exam trap

EC-Council often tests the misconception that booting from a live CD is safe because it doesn't touch the hard drive, but in reality, even a live CD can modify the system's registry, page file, or metadata through normal operation, which is why seizing the computer for lab imaging is the only forensically sound option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Seize the computer and transport it to a forensic lab for imaging.

When a suspect's computer is already turned off, the best procedure is to seize it and transport it to a forensic lab for imaging. This preserves the integrity of the evidence by preventing any accidental modification of the hard drive's contents, which could occur if the system is powered on or booted from a live CD. In forensic best practices, the first responder should never boot a suspect's computer, as doing so can alter critical system files, timestamps, and volatile data, compromising the chain of custody and admissibility of evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Compute a hash of the hard drive using a live CD.

    Why it's wrong here

    Booting a forensic live CD alters the system state: it reads/writes to the disk (e.g., swap, temporary files, and access times) and leaves traces that undermine evidentiary integrity. Hashing an active disk also yields a non-consistent snapshot, whereas proper acquisition requires a hardware write-blocker and a bit-for-bit image captured in a controlled environment.

  • Check the power cord and peripherals for tampering.

    Why it's wrong here

    Inspecting the power cord and peripherals for tampering is a valid physical triage step, but doing so before seizing the system risks losing volatile data if cables are disconnected and delays the priority of preserving the device under chain of custody. Physical tampering evidence should be documented and packaged, yet the mission-critical action is to secure and transport the computer for controlled forensic analysis.

  • Seize the computer and transport it to a forensic lab for imaging.

    Why this is correct

    Seizing the computer and transporting it to a forensic lab preserves the original evidence for a proper bit-for-bit image using a write-blocker, ensuring data integrity and admissibility. A controlled lab environment allows for secure storage and careful analysis before any acquisition, maintaining a documented chain of custody from the scene onward. This is the recognized best practice for first responders.

  • Turn on the computer to see if it boots normally.

    Why it's wrong here

    Powering on the suspect computer triggers writes to the pagefile, registry, and file system metadata (such as last access times), and may also trigger encryption or decryption operations. Additionally, without first capturing RAM, you destroy volatile evidence that exists only in memory. A forensic first responder must never boot the suspect system; the correct action is to preserve its state exactly as found.

About these practice questions

One of 205 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.