CHFI Evidence Acquisition and Duplication Practice Question
A forensic investigator is preparing to acquire a USB flash drive that is suspected to contain evidence of intellectual property theft. The investigator needs to ensure that the acquisition process does not alter any data on the flash drive. Which of the following should the investigator use?
⚠ Common exam trap
The trap here is assuming that a software write blocker or 'dd' command provides the same level of protection as a hardware write blocker, but only a hardware blocker physically prevents writes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A hardware write blocker
A hardware write blocker is the most reliable way to prevent any writes to the USB flash drive during acquisition. It physically intercepts write commands, ensuring the drive remains unaltered. Software write blockers and 'dd' do not offer the same level of guaranteed protection, and a USB hub has no write-blocking capability. Therefore, a hardware write blocker is the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A software write blocker
Why it's wrong here
A software write blocker runs on the forensic workstation and can prevent writes, but it is less reliable than a hardware blocker because it depends on the operating system and can be bypassed by certain drivers or malware. For a USB flash drive, a hardware write blocker is preferred for guaranteed protection. Software blockers are more suitable for internal drives when hardware blockers are not available.
- ✓
A hardware write blocker
Why this is correct
A hardware write blocker prevents any write commands from reaching the USB flash drive, ensuring that the data remains unaltered. It is a physical device that intercepts and blocks writes at the hardware level, providing strong protection against accidental modification. This is the standard tool for forensic acquisition to maintain evidential integrity.
- ✗
The 'dd' command with the 'if' and 'of' parameters
Why it's wrong here
The 'dd' command itself does not prevent writes to the source drive; it merely copies data. Without a write blocker, there is a risk that the operating system could write to the USB drive during acquisition. Therefore, 'dd' alone is insufficient to ensure the drive is not altered.
- ✗
A USB hub with power management
Why it's wrong here
A USB hub with power management does not block write commands; it only manages power distribution. It provides no protection against data modification. Using such a hub would not prevent the forensic workstation from writing to the flash drive, so it is not a suitable tool for maintaining evidence integrity.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.