CHFI Computer Forensics Lab Practice Question
A forensic lab manager is setting up a new lab and must decide on the physical security measures. Which of the following is the MOST important to implement first?
⚠ Common exam trap
The trap here is that candidates often prioritize surveillance (CCTV) or evidence preservation (Faraday cages) over the foundational security principle of access control, failing to recognize that without controlling who enters, all other measures are reactive rather than preventive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a biometric access control system
Biometric access control is the most critical first step because it establishes a foundational layer of physical security that authenticates and authorizes personnel before they can access the lab. Without controlling who enters, other measures like CCTV or fire suppression are less effective, as unauthorized individuals could compromise evidence integrity. This aligns with the principle of defense-in-depth, where access control is the primary barrier against tampering or theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Construct Faraday cages around the evidence storage area
Why it's wrong here
Faraday cages are primarily designed to attenuate electromagnetic signals, preventing wireless data exfiltration or remote tampering, but they offer no physical barrier to unauthorized human access. A forensic lab's evidence storage area needs to resist forced entry, theft, and insider misuse; a Faraday cage's conductive mesh does not address locks, door hardening, or authentication. Thus, while it may be a specialized safeguard for certain electronic evidence, it is not a core access control measure and would not be the first security investment in a new lab.
- ✗
Deploy CCTV cameras covering all entry points
Why it's wrong here
CCTV systems are detective controls that document events after they occur, capturing video of entry attempts or suspicious activity, but they lack the capability to physically prevent or authenticate access in real time. An intruder can bypass a camera entirely or disable it, and the system will not deny entry to an unauthorized person. Effective physical security requires a preventive mechanism such as a biometric or card-based access control system at the door, with CCTV serving as an ancillary monitoring and evidence-collection tool, not as the primary control.
- ✗
Install a gas-based fire suppression system
Why it's wrong here
Gas-based fire suppression protects against environmental hazards by flooding an area with inert gas or chemical agents to extinguish fires, but it is unrelated to unauthorized human access or evidence handling. It is a life-safety and asset-preservation system that operates only during a fire event, providing no authentication, intrusion detection, or barrier to entry. In a forensic lab, the most immediate threat is human compromise of evidence chain of custody, so access control must precede fire safety in priority, even though both are essential for comprehensive lab resilience.
- ✓
Implement a biometric access control system
Why this is correct
Biometric access control authenticates individuals using unique physiological characteristics—such as fingerprints, iris patterns, or facial geometry—making it nearly impossible to lend, steal, or duplicate credentials. This enforces physical access as a preventive control, ensuring only pre-authorized personnel enter evidence storage areas, thereby maintaining chain of custody and legal defensibility. Unlike keys or cards, biometrics provide non-repudiation because each entry attempt is tied to a specific person and can be logged for audit. It directly addresses the foundational risk of unauthorized access, which is the first and most critical security requirement for a forensic lab.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.