Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A security analyst arrives at a crime scene where a computer is turned on and the screen shows a document. What is the FIRST action the analyst should take according to forensic best practices?

⚠ Common exam trap

EC-Council often tests the misconception that preserving volatile data means immediately pulling the plug, when in fact the correct first step is to document the live state to avoid destroying evidence that cannot be recovered.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Photograph the screen and surroundings, then proceed to document the scene.

The first priority at a live crime scene is to preserve the state of the system and its environment through documentation. Photographing the screen and surroundings captures volatile data (e.g., open documents, running processes, network connections) before any interaction alters the system. This aligns with the order of volatility and the principle of minimizing changes to the evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a forensic image of the hard drive using a write blocker.

    Why it's wrong here

    Creating a forensic image with a write blocker is an essential preservation step, but it is not the initial response because it requires the system to be powered down and the drive removed. Performing imaging before documenting the scene and capturing volatile memory would lose transient evidence (RAM, processes, network state) that exists only while the machine is running. The write blocker only protects the storage medium during acquisition; it cannot recover data lost due to premature shutdown. Thus, imaging is reserved for later in the workflow, after documentation and memory acquisition are complete.

  • ✗

    Open the Task Manager to check for suspicious processes.

    Why it's wrong here

    Opening Task Manager on the live system is an interactive action that inherently alters the evidence being collected. The tool itself launches new processes, updates prefetch and Registry keys, changes memory page tables, and modifies file access times, all of which contaminate the forensic timeline. Suspicious process analysis must be performed using read-only command-line tools (e.g., `ps` in a trusted environment) or after creating a memory image, never through the native GUI. This preserves the integrity of volatile data while still allowing investigation.

  • ✗

    Immediately unplug the power cord to preserve volatile data.

    Why it's wrong here

    Immediately unplugging the power cord is often a misconceived attempt to preserve evidence, but it actually destroys the most volatile data—RAM, including running processes, open network sockets, encryption keys, and unsaved data. While it halts writes to disk, it leaves the file system in an potentially inconsistent state and eliminates the ability to capture a memory dump. The proper procedure is to first document the scene, then acquire volatile memory using a dedicated forensic tool, and finally perform a controlled shutdown before handling the disk. Unplugging is only a last resort when avoiding an active data-destruction process or physical hazard.

  • ✓

    Photograph the screen and surroundings, then proceed to document the scene.

    Why this is correct

    Photographing the screen and surroundings is the correct first action because it captures the live visual state of the system without any interaction that could change it. This documentation preserves evidence of on-screen content, open applications, connected peripherals, and environmental context—vital for reconstructing the incident and establishing chain of custody. It also serves as a baseline for every subsequent action, ensuring the investigation is legally defensible. Only after this non-invasive step should any data collection or system interaction begin.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.