CHFI Computer Forensics Fundamentals and Process Practice Question
A forensic examiner is preparing to acquire a forensic image of a running Windows 10 laptop suspected of containing evidence of intellectual property theft. The examiner must capture volatile data that could be lost if the system is shut down. Which TWO of the following actions should the examiner take to preserve volatile evidence before imaging? (Choose two.)
⚠ Common exam trap
The trap here is prioritizing disk imaging or system shutdown over volatile data capture, which would irreversibly lose critical evidence like RAM contents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run the command 'netstat -an' to record active network connections.
Volatile data such as RAM contents and active network connections are lost when a system is powered off. Capturing RAM with a specialized tool preserves running processes, encryption keys, and other memory-resident evidence. Recording network connections with 'netstat -an' captures a snapshot of current communications. These steps must be taken before any disk imaging or shutdown to comply with the order of volatility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run the command 'netstat -an' to record active network connections.
Why this is correct
The 'netstat -an' command displays active network connections and listening ports, which are volatile and lost upon shutdown. This information can reveal remote access, data exfiltration, or command-and-control communications. Recording it before imaging ensures the examiner captures a snapshot of network activity. While not as comprehensive as a full memory dump, it is a quick, low-impact way to preserve a key piece of volatile evidence.
- ✗
Run 'chkdsk /f' to ensure the file system is consistent before imaging.
Why it's wrong here
'chkdsk /f' attempts to fix file system errors and can modify the disk, potentially destroying evidence. It also may cause writes to the disk, violating the principle of minimizing alteration. In forensics, the examiner should never run repair utilities on evidence. Instead, the disk should be write-blocked and imaged without modification. This action is inappropriate and harmful to the investigation.
- ✗
Create a forensic image of the hard drive using FTK Imager before capturing RAM.
Why it's wrong here
Imaging the hard drive first is a mistake because it takes time and may alter volatile data. The order of volatility dictates that RAM and network state should be captured before disk imaging. Disk imaging tools may also cause writes to the disk or consume system resources that affect memory contents. Therefore, RAM capture and network state recording must precede disk imaging to preserve the most perishable evidence.
- ✗
Immediately shut down the laptop to prevent remote wipe or tampering.
Why it's wrong here
Shutting down the laptop would destroy volatile data in RAM and active network connections. The scenario explicitly requires capturing volatile evidence, so powering off is counterproductive. While remote wipe is a concern, proper forensic procedures involve isolating the system from the network (e.g., disabling Wi-Fi) rather than shutting down. Shutdown also complicates the acquisition of encrypted drives if keys are only in memory.
- ✓
Capture the contents of RAM using a tool such as WinPmem or Magnet RAM Capture.
Why this is correct
RAM contains valuable volatile data including running processes, network connections, encryption keys, and unencrypted passwords. Tools like WinPmem or Magnet RAM Capture can create a memory dump without altering the system significantly. This must be done before any other acquisition because powering off or rebooting the system will erase RAM contents. Capturing RAM first preserves critical evidence that may not exist on the disk.
Go deeper
Related to this question
Learn chapter
Data Acquisition and Duplication Techniques
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
Disk Imaging
Disk imaging is the process of creating an exact, bit-for-bit copy of a storage drive, preserving all data, deleted files, and unallocated space for forensic analysis or system recovery.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.