CHFI Computer Forensics Fundamentals and Process Practice Question
An organization receives a legal hold notice regarding a pending lawsuit. The IT department is instructed to preserve all relevant electronically stored information (ESI). Which of the following actions must be taken FIRST?
⚠ Common exam trap
EC-Council often tests the misconception that forensic analysis or data collection should be the immediate step, when in fact the legal hold requires first stopping any automated destruction mechanisms to preserve the current state of ESI.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately suspend any automated data deletion policies
When a legal hold notice is issued, the first priority is to preserve all potentially relevant ESI by immediately suspending any automated data deletion policies (e.g., retention schedules, auto-archiving, or purge scripts). This prevents spoliation of evidence before any collection or analysis begins. Failure to do so could result in sanctions for destroying discoverable data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a full forensic analysis of all systems
Why it's wrong here
Conducting a full forensic analysis immediately is premature and counterproductive; the primary duty upon receiving a legal hold is to preserve evidence, not to investigate it. Forensic imaging and analysis must follow a documented chain of custody and use validated tools, and premature analysis could alter timestamps or introduce contamination if the systems are not properly acquired. The organization should first implement a litigation hold and preserve all potentially relevant ESI, then later determine what, if any, forensic examination is needed.
- ✗
Notify all employees to delete personal files
Why it's wrong here
Telling employees to delete personal files is dangerous because employees cannot reliably distinguish personal from business-relevant data, and the deletion of any file may destroy evidence that falls within the scope of the legal hold. Such an instruction implies an intent to dispose of records, which courts may view as spoliation or an attempt to defeat the duty to preserve. The organization must instead issue a clear directive to retain all potentially relevant data, and personal files should be preserved temporarily until their relevance can be assessed.
- ✓
Immediately suspend any automated data deletion policies
Why this is correct
Automated data deletion policies—such as email retention schedules, log rotation, or scripted file cleanup—can irretrievably destroy ESI that is subject to the legal hold, often without human intervention. Immediately suspending those routines stops the clock and preserves the current state of all potentially relevant data, which is the foundational step of a valid litigation hold. This suspension should be documented and disseminated to IT staff to prevent any scheduled jobs from running overnight or at the next backup cycle.
- ✗
Delete all emails older than 30 days to reduce storage
Why it's wrong here
Deleting emails older than 30 days constitutes affirmative spoliation because email age is irrelevant to whether a message contains discoverable information; old emails may be central to the anticipated litigation. Storage constraints do not excuse destruction when a legal hold is in effect, and such deletion would likely trigger an adverse inference instruction or monetary sanctions. The organization should instead preserve all email in place, even at the cost of increased storage, and address capacity issues through approved means that do not destroy data.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.