Courseiva
Computer Forensics Lab →easyMultiple Choice

CHFI Computer Forensics Lab Practice Question

A junior examiner is preparing a forensics lab workstation that will be used to image suspect drives. The lab policy states the workstation must never write to a connected suspect drive. Which practice ensures this requirement is met?

⚠ Common exam trap

The trap here is assuming that a read-only attribute or a mapped network drive is equivalent to a hardware write-blocker, when only the hardware device reliably blocks writes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connect the suspect drive through a hardware write-blocker before imaging

Imaging suspect media without altering it requires a hardware write-blocker placed between the workstation and the drive. Software attributes, encryption, and network mapping do not guarantee the drive stays unmodified. The write-blocker enforces read-only at the interface level, which is the accepted lab practice for preserving evidence integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Connect the suspect drive through a hardware write-blocker before imaging

    Why this is correct

    A hardware write-blocker physically intercepts write commands on the interface, so the suspect drive cannot be modified during imaging. This is the standard lab practice for preserving evidence integrity and is expected by CHFI when acquiring suspect media. Using it before imaging ensures the original drive remains unaltered and the hash of the source matches the image.

  • ✗

    Enable BitLocker on the suspect drive before connecting it

    Why it's wrong here

    Enabling BitLocker would encrypt the suspect drive and change its contents, directly violating the requirement to avoid writing to it. BitLocker is a data-protection feature for live systems, not an evidence-preservation control. This action would also complicate later analysis because the examiner would need recovery keys that may not be available.

  • ✗

    Mount the suspect drive with the read-only attribute set in Windows Disk Management

    Why it's wrong here

    Disk Management does not provide a dependable read-only mount for suspect media, and Windows can still write metadata such as last-access timestamps or mount points. A software-level attribute is not equivalent to a hardware write-blocker. Relying on it risks altering the evidence and invalidating the acquisition in court.

  • ✗

    Image the drive over the network using a mapped drive letter

    Why it's wrong here

    Mapping a drive letter still exposes the suspect volume to the operating system, which may update file system metadata during access. Network mapping does not enforce a write block and can introduce writes from the host OS. This approach does not satisfy the non-modification requirement and is discouraged for suspect media.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.