CHFI Computer Forensics Fundamentals and Process Practice Question
A security analyst responds to a suspected data breach. The analyst documents the scene, photographs the computer, and labels the cables. Which phase of the forensic investigation process is being performed?
⚠ Common exam trap
EC-Council often tests the distinction between First Response and Collection, where candidates mistakenly think that any hands-on action (like labeling cables) is part of Collection, but Collection specifically refers to the technical acquisition of data, not scene preservation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
First response
The actions described—documenting the scene, photographing the computer, and labeling cables—are part of the First Response phase. This phase occurs immediately after an incident is detected and focuses on preserving the integrity of the scene and evidence before any collection or analysis begins. In the CHFI methodology, First Response includes securing the area, creating a detailed log of the initial state, and ensuring no unauthorized changes occur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Collection
Why it's wrong here
Collection is the formal phase of the forensic methodology that involves systematically acquiring digital evidence using validated tools (e.g., FTK Imager, dd) and documenting a strict chain of custody. It presupposes that the incident scene is already secured and that transient, volatile data (RAM, active processes, network connections) has been preserved. In a suspected breach, the immediate priority is to stabilize the environment and capture time-sensitive state—these are first-response actions, not collection. Choosing Collection is incorrect because it skips the urgent, initial preservation phase that must occur first.
- ✓
First response
Why this is correct
First response is correct because it comprises the initial, time-critical actions: securing the scene, identifying the scope of compromise, preserving volatile evidence (memory, running processes, network sockets), and documenting the exact system state and time. These actions prevent further data loss and ensure that fleeting digital artifacts are not destroyed by powering down or by ongoing attacker activity. Framework guidance such as NIST SP 800-86 and ISO 27037 explicitly places scoping and preservation at the outset, before any formal collection or analysis. Thus, the first step in a suspected breach is the first response, not a later forensic phase.
- ✗
Examination
Why it's wrong here
Examination is a subsequent phase in the forensic workflow, focused on deep technical analysis of the acquired evidence—such as signature-based scanning, file carving, timeline reconstruction, and behavioral analysis of malware or attacker tactics. It is performed on static copies after first response and formal collection are complete, and it cannot occur before the evidence is secured. In a suspected breach, examination is not the initial action because the scene must first be contained and preserved. This option is wrong because it misidentifies the investigative analysis phase as the starting point, ignoring the necessary preservation of volatile evidence.
- ✗
Reporting
Why it's wrong here
Reporting is the terminal phase of a digital forensic investigation, where the examiner synthesizes findings, conclusions, and supporting exhibits into a formal report for management, legal counsel, or law enforcement. It depends entirely on the evidence obtained and analyzed during collection and examination; it is the end product, not the first step. In a suspected breach, reporting is irrelevant until the incident is investigated and resolved. Choosing Reporting reflects a fundamental chronological error, because immediate response actions—containment and preservation—must occur long before any formal report is produced.
Go deeper
Related to this question
Learn chapter
Data Acquisition and Duplication Techniques
Key term
Volatility Framework
An open-source memory forensics tool used to extract digital evidence from a computer's RAM (random access memory).
Key term
Disk Imaging
Disk imaging is the process of creating an exact, bit-for-bit copy of a storage drive, preserving all data, deleted files, and unallocated space for forensic analysis or system recovery.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.