CHFI Computer Forensics Lab Practice Question
A forensics lab is preparing a new acquisition workstation for imaging suspect drives. The lab manager wants to ensure the workstation itself does not introduce evidence contamination or alter suspect media during imaging. Which two practices should be implemented? (Choose two.)
⚠ Common exam trap
The trap here is thinking that faster or more convenient configurations, such as booting from the suspect drive, are acceptable when they actually alter the evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a hardware write-blocker between the workstation and the suspect drive
The two practices that directly prevent contamination and alteration are using a hardware write-blocker and verifying the image hash against the source. The write-blocker stops writes to the suspect drive, and the hash comparison proves the image is an exact copy. The other options either modify the suspect drive, introduce unrelated data, or do not address evidence integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install the suspect drive's original operating system on the workstation to match the environment
Why it's wrong here
Installing the suspect's operating system on the workstation would introduce unrelated data and could alter the workstation's forensic toolset. It also risks the workstation writing to the suspect drive if the OS recognizes it. The workstation should remain a controlled, clean environment, not a replica of the suspect system.
- ✓
Use a hardware write-blocker between the workstation and the suspect drive
Why this is correct
A hardware write-blocker prevents the workstation from writing to the suspect drive, preserving the original media during imaging. This is a core lab practice to avoid evidence contamination and to ensure the source hash matches the image. Without it, the workstation could modify file system metadata and invalidate the acquisition.
- ✗
Disable the workstation's antivirus to improve imaging speed
Why it's wrong here
Disabling antivirus does not prevent contamination and may expose the workstation to malware from suspect media. It also does not address the requirement to keep the suspect drive unmodified. Antivirus should be managed according to lab policy, but it is not a substitute for a write-blocker or hash verification.
- ✓
Verify the acquired image hash against the source drive hash after imaging
Why this is correct
Comparing the image hash to the source hash confirms the acquisition is a bit-for-bit copy and that no alteration occurred. This verification step is expected in CHFI labs and supports the integrity claim in court. If hashes differ, the examiner knows the image is unreliable and must re-acquire.
- ✗
Connect the suspect drive as the primary boot device to speed up access
Why it's wrong here
Booting from the suspect drive would cause the operating system to write to it, altering evidence and defeating the purpose of the acquisition. The suspect drive must never be the boot device. Imaging should occur with the drive connected as a secondary, read-only device through a write-blocker.
Go deeper
Related to this question
Learn chapter
Data Acquisition and Duplication Techniques
Key term
Disk Imaging
Disk imaging is the process of creating an exact, bit-for-bit copy of a storage drive, preserving all data, deleted files, and unallocated space for forensic analysis or system recovery.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.