Courseiva

CHFI Evidence Acquisition and Duplication Practice Question

A forensic examiner is acquiring a running Linux server that is part of a live incident response. The server hosts a critical database and cannot be taken offline. The examiner needs to capture volatile data in a forensically sound manner. Which TWO of the following actions should the examiner perform? (Choose two.)

⚠ Common exam trap

Many candidates confuse volatile data acquisition with full disk imaging, or thinking that system maintenance commands like fsck are part of live response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture network connections using the 'netstat' command

Capturing running processes with 'ps' and network connections with 'netstat' are standard volatile data collection steps that do not disrupt the server. They provide critical information about active threats and can be performed quickly. Full disk imaging and file system checks are either disruptive or irrelevant to volatile data, and deleting files destroys evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete temporary files to free up space for acquisition

    Why it's wrong here

    Deleting temporary files modifies the system and destroys potential evidence. It is a direct violation of forensic principles, as it alters the original state. This action would compromise the investigation and is never acceptable during evidence acquisition.

  • ✗

    Use the 'dd' command to create a full disk image of the server's primary drive

    Why it's wrong here

    Creating a full disk image of a live server's primary drive is not a volatile data acquisition step and can be highly disruptive. It may cause performance degradation, and the image may be inconsistent due to ongoing writes. It also does not capture volatile data like memory or network connections, so it is not appropriate for this scenario.

  • ✓

    Capture network connections using the 'netstat' command

    Why this is correct

    The 'netstat' command displays active network connections, listening ports, and associated processes. This volatile data is crucial for identifying command-and-control channels or data exfiltration. It can be collected quickly without impacting the server's operation, making it a correct action for live volatile data acquisition.

  • ✗

    Run 'fsck' on the primary drive to check for file system inconsistencies

    Why it's wrong here

    Running 'fsck' on a mounted file system is dangerous and can cause data corruption. It is not a volatile data collection method and could alter the evidence. This action would compromise the integrity of the system and is not appropriate for live incident response.

  • ✓

    Collect the output of the 'ps' command to capture running processes

    Why this is correct

    The 'ps' command lists currently running processes, which are volatile and would be lost on shutdown. Capturing this data provides insight into active malicious processes, their PIDs, and parent-child relationships. It is a standard live response step and can be done without disrupting the system, making it a correct action for volatile data acquisition.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.