Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A security analyst discovers unauthorized access to a server. The incident response team decides to preserve evidence. Which of the following actions is MOST critical to ensure the admissibility of evidence in court?

⚠ Common exam trap

EC-Council often tests the misconception that immediate network disconnection is the top priority, but the CHFI exam emphasizes that preserving the integrity and admissibility of evidence through chain of custody outweighs technical containment actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Documenting the chain of custody

Chain of custody documentation is the most critical action for evidence admissibility because it establishes a verifiable record of who handled the evidence, when, and under what conditions, ensuring the evidence has not been tampered with. Without a proper chain of custody, even technically sound evidence can be ruled inadmissible under rules like Federal Rule of Evidence 901. In forensic practice, this involves logging every access with timestamps, digital signatures, and hash values (e.g., SHA-256) to maintain integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disconnecting the server from the network

    Why it's wrong here

    Disconnecting the server from the network is a reactive containment step that halts further remote access and preserves volatile data, but it does not create the legally required documentation of evidence provenance. The act itself modifies the system state—active network connections are terminated and system processes may change—and without a contemporaneous record of that action, opposing counsel can argue the evidence is not trustworthy. Admissibility depends on demonstrating that the evidence remained unaltered from seizure onward, which requires a documented chain of custody, not merely a technical isolation event.

  • ✓

    Documenting the chain of custody

    Why this is correct

    Documenting the chain of custody is the foundational act that makes digital evidence legally admissible because it establishes an unbroken record of who handled the evidence, when, how, and where it was stored. This record demonstrates that the evidence cannot have been substituted, tampered with, or contaminated between the moment of discovery and its presentation in court. Without it, the evidence is subject to exclusion on the grounds that its authenticity cannot be verified, regardless of how technically sound the other forensic steps were.

  • ✗

    Running a full antivirus scan on the server

    Why it's wrong here

    Running a full antivirus scan is a forensic analysis action that should be performed on a forensic copy of the original data, not the live server, because the scan itself alters evidence—file access times are updated, quarantined files are moved, logs are written, and the scan engine may modify the very artifacts it is inspecting. This alteration undermines the integrity of the original evidence and, without a documented chain of custody proving that the evidence was already in a reliable state, any conclusions drawn from the scan will be challenged. The priority during initial response is to preserve the original state and document its custody, not to perform potentially intrusive scans that could destroy the evidentiary value.

  • ✗

    Taking screenshots of the server's screen

    Why it's wrong here

    Taking screenshots of the server's screen provides a transient visual record of what was displayed at a given moment, which can be helpful for context, but it is not sufficient to ensure legal admissibility because screenshots do not establish the integrity or provenance of the underlying digital data. A screenshot can be easily manipulated, edited, or taken out of context, and it offers no verifiable metadata linking it to the original server state at the time of the incident. Chain of custody is the critical factor because it provides a forensic, verifiable trail of evidence handling, whereas a screenshot is simply a secondary representation that cannot support a legal argument on its own.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.