Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

An organization receives a legal hold notice regarding a pending lawsuit. The IT department is instructed to preserve all relevant electronically stored information (ESI). Which of the following actions must be taken FIRST?

⚠ Common exam trap

EC-Council often tests the misconception that forensic analysis or data collection should be the immediate step, when in fact the legal hold requires first stopping any automated destruction mechanisms to preserve the current state of ESI.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately suspend any automated data deletion policies

When a legal hold notice is issued, the first priority is to preserve all potentially relevant ESI by immediately suspending any automated data deletion policies (e.g., retention schedules, auto-archiving, or purge scripts). This prevents spoliation of evidence before any collection or analysis begins. Failure to do so could result in sanctions for destroying discoverable data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a full forensic analysis of all systems

    Why it's wrong here

    Conducting a full forensic analysis immediately is premature and counterproductive; the primary duty upon receiving a legal hold is to preserve evidence, not to investigate it. Forensic imaging and analysis must follow a documented chain of custody and use validated tools, and premature analysis could alter timestamps or introduce contamination if the systems are not properly acquired. The organization should first implement a litigation hold and preserve all potentially relevant ESI, then later determine what, if any, forensic examination is needed.

  • ✗

    Notify all employees to delete personal files

    Why it's wrong here

    Telling employees to delete personal files is dangerous because employees cannot reliably distinguish personal from business-relevant data, and the deletion of any file may destroy evidence that falls within the scope of the legal hold. Such an instruction implies an intent to dispose of records, which courts may view as spoliation or an attempt to defeat the duty to preserve. The organization must instead issue a clear directive to retain all potentially relevant data, and personal files should be preserved temporarily until their relevance can be assessed.

  • ✓

    Immediately suspend any automated data deletion policies

    Why this is correct

    Automated data deletion policies—such as email retention schedules, log rotation, or scripted file cleanup—can irretrievably destroy ESI that is subject to the legal hold, often without human intervention. Immediately suspending those routines stops the clock and preserves the current state of all potentially relevant data, which is the foundational step of a valid litigation hold. This suspension should be documented and disseminated to IT staff to prevent any scheduled jobs from running overnight or at the next backup cycle.

  • ✗

    Delete all emails older than 30 days to reduce storage

    Why it's wrong here

    Deleting emails older than 30 days constitutes affirmative spoliation because email age is irrelevant to whether a message contains discoverable information; old emails may be central to the anticipated litigation. Storage constraints do not excuse destruction when a legal hold is in effect, and such deletion would likely trigger an adverse inference instruction or monetary sanctions. The organization should instead preserve all email in place, even at the cost of increased storage, and address capacity issues through approved means that do not destroy data.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.