Courseiva
Computer Forensics Fundamentals and ProcessmediumMultiple ChoiceObjective-mapped

CHFI Computer Forensics Fundamentals and Process Practice Question

An organization receives a legal hold notice regarding pending litigation. The IT department is instructed to preserve all relevant electronically stored information. What is the primary action the IT department should take?

⚠ Common exam trap

EC-Council often tests the misconception that the immediate response to a legal hold is to create forensic images of all systems, but the correct first step is to suspend deletion policies to prevent data loss before any imaging or collection occurs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Place a hold on relevant data and suspend routine deletion policies

The primary action is to place a legal hold on relevant data and suspend routine deletion policies. This ensures that all potentially relevant electronically stored information (ESI) is preserved in its current state, preventing spoliation and compliance with the legal hold notice. Suspending deletion policies stops automated processes like email purge jobs or document retention schedules from destroying evidence, which is a foundational step in the e-discovery process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Place a hold on relevant data and suspend routine deletion policies

    Why this is correct

    A legal hold triggers a duty to preserve all potentially relevant data in their native form, so you must place a litigation hold on the specific systems, files, email mailboxes, and backups that could contain responsive information. This includes actively suspending any automated deletion, archival, or retention policies that would destroy or alter that data, ensuring it remains intact and available for later discovery without necessarily needing forensic duplication.

  • Ignore the notice and continue normal operations

    Why it's wrong here

    Ignoring a legal hold notice is a direct violation of the duty to preserve evidence once litigation is reasonably anticipated, and it exposes the organization to spoliation sanctions, adverse inference instructions, or monetary penalties under rules like FRCP 37(e). Even without intentional destruction, the failure to take reasonable steps to preserve data can be treated as gross negligence, undermining the organization's credibility and weakening its defense.

  • Create a forensic image of all servers immediately

    Why it's wrong here

    Imaging every server in the environment is overbroad and disproportionate to the legal hold requirement, because preservation only needs to protect data that is potentially relevant, custodian-specific, or otherwise responsive to the matter. Forensic imaging is a valid collection method, but performing it on all infrastructure without scoping causes unnecessary expense, downtime, and storage overhead, and it may also capture sensitive unrelated data that expands the discovery burden.

  • Permanently delete all emails older than 30 days to reduce storage

    Why it's wrong here

    Permanently deleting all emails older than 30 days is a classic spoliation act that destroys potentially relevant evidence and directly violates the legal hold's duty to suspend routine retention and destruction schedules. If the deletion occurs after the notice was received, the court may infer the evidence was unfavorable, leading to severe sanctions such as adverse inference instructions, case-dispositive penalties, or cost shifting.

About these practice questions

Courseiva writes every CHFI question from scratch — 205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.