CHFI Computer Forensics Lab Practice Question
A junior examiner is preparing a forensics lab workstation that will be used to image suspect drives. The lab policy states the workstation must never write to a connected suspect drive. Which practice ensures this requirement is met?
⚠ Common exam trap
The trap here is assuming that a read-only attribute or a mapped network drive is equivalent to a hardware write-blocker, when only the hardware device reliably blocks writes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connect the suspect drive through a hardware write-blocker before imaging
Imaging suspect media without altering it requires a hardware write-blocker placed between the workstation and the drive. Software attributes, encryption, and network mapping do not guarantee the drive stays unmodified. The write-blocker enforces read-only at the interface level, which is the accepted lab practice for preserving evidence integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Connect the suspect drive through a hardware write-blocker before imaging
Why this is correct
A hardware write-blocker physically intercepts write commands on the interface, so the suspect drive cannot be modified during imaging. This is the standard lab practice for preserving evidence integrity and is expected by CHFI when acquiring suspect media. Using it before imaging ensures the original drive remains unaltered and the hash of the source matches the image.
- ✗
Enable BitLocker on the suspect drive before connecting it
Why it's wrong here
Enabling BitLocker would encrypt the suspect drive and change its contents, directly violating the requirement to avoid writing to it. BitLocker is a data-protection feature for live systems, not an evidence-preservation control. This action would also complicate later analysis because the examiner would need recovery keys that may not be available.
- ✗
Mount the suspect drive with the read-only attribute set in Windows Disk Management
Why it's wrong here
Disk Management does not provide a dependable read-only mount for suspect media, and Windows can still write metadata such as last-access timestamps or mount points. A software-level attribute is not equivalent to a hardware write-blocker. Relying on it risks altering the evidence and invalidating the acquisition in court.
- ✗
Image the drive over the network using a mapped drive letter
Why it's wrong here
Mapping a drive letter still exposes the suspect volume to the operating system, which may update file system metadata during access. Network mapping does not enforce a write block and can introduce writes from the host OS. This approach does not satisfy the non-modification requirement and is discouraged for suspect media.
Go deeper
Related to this question
Learn chapter
Evidence Handling and Chain of Custody
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
Disk Imaging
Disk imaging is the process of creating an exact, bit-for-bit copy of a storage drive, preserving all data, deleted files, and unallocated space for forensic analysis or system recovery.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.