CHFI Computer Forensics Lab Practice Question
A forensic lab is designing a network architecture to ensure the integrity of evidence during acquisition. What is the most critical design consideration?
⚠ Common exam trap
A common mix-up: candidates confuse network security measures (segmentation, encryption) with evidence integrity controls, failing to recognize that the most critical design consideration is preventing any write access to the source media at the hardware level during acquisition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement hardware write-blockers on all acquisition stations
Hardware write-blockers are the most critical design consideration because they physically prevent any write operations to the source drive at the ATA/SCSI command level, ensuring that the evidence remains bit-for-bit unchanged during acquisition. Without a hardware write-blocker, even a single read operation from a forensic workstation could inadvertently modify metadata (e.g., last access timestamps) or trigger anti-forensic mechanisms, compromising the integrity of the evidence and its admissibility in court.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy multiple forensic workstations to parallelize tasks
Why it's wrong here
Adding more forensic workstations to parallelize evidence processing only reduces total processing time and improves resource utilization; it does not address whether the source media remains bit-for-bit unchanged during acquisition. Forensic integrity is established by write protection and cryptographic hash verification at the moment of collection, not by the number of machines available. In fact, using multiple stations creates additional device and cabling variables that require separate validation, but parallelism itself neither verifies nor preserves integrity.
- ✗
Use a segmented network to isolate forensic tools
Why it's wrong here
Network segmentation, such as VLANs and air-gapped enclaves, protects forensic tools and evidence stores from external attack, malware propagation, and unauthorized access, but it does not prevent a drive from being altered while a forensic system acquires it. The integrity requirement concerns the source evidence media, not the network perimeter; segmentation has no mechanism to intercept or block write commands issued to a storage device. Even a perfectly isolated workstation will alter the exhibit unless a write-blocker is used.
- ✗
Encrypt all data in transit over the network
Why it's wrong here
Encrypting data in transit with TLS/SSH or IPSec preserves the confidentiality and often the authenticity of files moving across the network, but it does nothing to protect the original source drive from modifications during acquisition. The forensic integrity question is about whether the source media's bits are preserved, not whether copied data is protected while traveling; encryption cannot stop the operating system from writing metadata, timestamps, or temporary files to an attached evidence drive. Moreover, if network encryption is misconfigured or keys are unavailable, it can impede evidence transfer, yet it still never enforces write-blocking at the acquisition interface.
- ✓
Implement hardware write-blockers on all acquisition stations
Why this is correct
A hardware write-blocker is inserted between the source drive and the forensic workstation, electrically or logically blocking write commands at the SATA/USB/IDE interface, so the operating system and forensic software cannot modify the original media under any circumstances. This is the direct technical control that preserves bit-for-bit integrity and enables valid cryptographic hash matching before and after acquisition. Using a write-blocker on every acquisition station is considered best practice in digital forensics and is required for standardized forensic imaging workflows.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.