CHFI Computer Forensics Fundamentals and Process Practice Question
A forensic examiner needs to acquire an image of a suspect's laptop hard drive. The laptop is running, and the examiner wants to capture volatile data first. According to best practices, which order of steps should the examiner follow?
⚠ Common exam trap
Many exam-takers think immediate power-off (Option A) preserves the disk state, but they forget that volatile data is lost and an unclean shutdown can corrupt the filesystem, making the image less reliable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture volatile data, then shut down normally, remove the drive, and image with a write blocker.
Forensic best practices mandate capturing volatile data (e.g., RAM, network connections, running processes) first, as this data is lost on power loss. After capturing volatile data, the examiner should perform a graceful shutdown to preserve file system integrity, then remove the drive and acquire a forensic image using a write blocker to prevent any modification to the original evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unplug the laptop, remove the drive, and boot the drive in a forensic workstation.
Why it's wrong here
Cutting AC power by unplugging instantly destroys all volatile memory—RAM holds encryption keys, open processes, and clipboard contents—and may also leave the NTFS/APFS journal in an inconsistent state. Booting the original drive afterward on a forensic workstation without first making an image risks writing timestamps and metadata to the evidence media. This method sacrifices the most fragile evidence at the earliest step, so it is not an acceptable acquisition workflow.
- ✗
Immediately remove the hard drive, then capture RAM from the drive.
Why it's wrong here
RAM is stored in volatile silicon, so once the laptop loses power it vanishes; you cannot later capture RAM 'from the drive' after physically removing it. Removing the hard drive while the machine is still running often requires a forced hot-unplug which can electrically damage the drive or corrupt its filesystem, making subsequent imaging unreliable. The correct sequence is to capture a RAM dump while the system is alive (using tools like win32dd or LiME), and only then power down and extract storage.
- ✗
Create a full disk image over the network while the laptop is running.
Why it's wrong here
Streaming a full disk image over the network injects a forensic agent into the live operating system, which modifies pagefiles, prefetch, and event logs, and the network transfer itself may time out or be intercepted. This approach also requires the suspect laptop to be connected to infrastructure that might be hostile or unavailable, and there is no hardware isolation of writes to the original disk. Forensically sound acquisition demands minimizing system modification; the first responder should collect volatile data locally, then perform a write-blocked static acquisition.
- ✓
Capture volatile data, then shut down normally, remove the drive, and image with a write blocker.
Why this is correct
Collecting RAM first preserves evidence of running processes, encryption keys, and open network connections before they vanish at power-down. A normal shutdown lets the OS flush journaled filesystems and VSS snapshots, avoiding the inconsistency caused by hard cuts. Removing the drive afterward and attaching it to a forensic write blocker ensures that all writes are blocked, then tooling such as FTK Imager or dc3dd creates a bit-identical image verified with SHA-256; this is the accepted order of operations in NIST/CHFI guidance.
Go deeper
Related to this question
Learn chapter
Evidence Handling and Chain of Custody
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.