Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A forensic analyst is creating a forensic image of a suspect's hard drive using a write blocker. Which of the following BEST describes the purpose of using a hardware write blocker?

⚠ Common exam trap

The CHFI exam often tests the misconception that a write blocker's purpose is to protect the destination drive or to speed up imaging, rather than its core function of write-protecting the source drive to maintain forensic integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To ensure that no data is written to the source drive during imaging

A hardware write blocker is a device placed between the suspect drive and the forensic workstation that intercepts and blocks any write commands from the operating system or imaging software. Its primary purpose is to guarantee that the source drive remains completely unaltered during acquisition, preserving the integrity of the evidence for legal and forensic purposes. This is achieved by allowing only read commands to pass through, while all write commands are physically or logically blocked at the hardware level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To ensure that no data is written to the source drive during imaging

    Why this is correct

    A hardware write blocker sits between the suspect drive and the forensic workstation, intercepting every ATA/SCSI/NVMe command and allowing only read-only commands (e.g., READ SECTOR, IDENTIFY) to pass through while suppressing destructive commands like WRITE and DELETE. This preserves the bit-for-bit original state, so hash values calculated on the source remain valid and the evidence is admissible in court.

  • ✗

    To increase the speed of data acquisition

    Why it's wrong here

    Write blockers introduce an additional protocol layer and command-processing overhead between the drive and the acquisition workstation, which can slightly reduce transfer throughput rather than increase it. Acquisition speed is primarily determined by the drive's interface bandwidth and the imaging tool's efficiency, not by the write blocker, which is designed solely for data protection.

  • ✗

    To encrypt the forensic image for secure storage

    Why it's wrong here

    Write blockers are electrically transparent to data content — they do not encrypt, decrypt, or transform the payload of a read command; they only filter command opcodes to enforce a read-only state. Encryption of the resulting forensic image must be performed by the imaging software (e.g., EnCase, FTK Imager, or `dd` piped to an encryptor) after acquisition, and a write blocker has no key storage or cipher engine.

  • ✗

    To allow the suspect drive to be booted without altering data

    Why it's wrong here

    Booting a suspect drive with a write blocker is not feasible because a normal OS boot requires writes to the file system — creating page files, updating last-access timestamps, and writing to system logs — which the write blocker is designed to block. Moreover, forensic imaging is performed on a 'dead' drive connected to a trusted forensic workstation, not by booting it, and booting the suspect drive would invalidate the forensic image by altering the source.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.