Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT administrator is instructed to preserve all relevant electronic records. Which of the following actions is MOST consistent with proper legal hold implementation?

⚠ Common exam trap

The CHFI exam often tests the misconception that data preservation means securing data through encryption or access control, rather than the core requirement of suspending deletion and notifying custodians to prevent spoliation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place a hold on all data that may be relevant by suspending routine deletion and notifying custodians.

A litigation hold (also known as a legal hold) requires suspending routine data deletion and preservation of potentially relevant electronically stored information (ESI). The IT administrator must notify custodians and implement a hold that prevents automated purging (e.g., via retention policies in Exchange or file servers) to comply with the duty to preserve evidence under FRCP Rule 37(e).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reboot all servers to ensure they are running the latest patches.

    Why it's wrong here

    Rebooting servers to apply patches is inappropriate during a litigation hold because a reboot clears volatile memory artifacts, processes, network connections, and cached credentials that may constitute evidence. More fundamentally, patch installation does not address the legal duty to preserve potentially relevant data; instead, it risks modifying file timestamps, locks, and service state, potentially compromising the chain of custody. Preservation requires immediate suspension of deletion and forensic imaging, not system maintenance.

  • ✗

    Immediately delete all emails older than 90 days to reduce data volume.

    Why it's wrong here

    Purging emails older than 90 days is an act of spoliation once a litigation hold has been issued, regardless of their age; even aged correspondence can contain relevant evidence, and applicable preservation obligations override routine retention policies. Proactively deleting data to reduce volume destroys discoverable ESI, exposes the organization to adverse inference instructions and monetary sanctions, and is directly contrary to the duty to preserve evidence. The proper action is to temporarily suspend all deletion policies and notify custodians.

  • ✓

    Place a hold on all data that may be relevant by suspending routine deletion and notifying custodians.

    Why this is correct

    The correct first step is to issue legal hold notices and suspend all routine deletion, retention-policy enforcement, and any automated purging processes for data that could plausibly relate to the litigation. This ensures the organization preserves electronically stored information (ESI) in its current form, maintains a defensible preservation process, and places custodians on notice of their obligation not to alter or destroy relevant data. A comprehensive litigation hold must also involve forensically preserving the data and identifying all sources (email, documents, databases, cloud systems) to satisfy discovery obligations.

  • ✗

    Encrypt all data and change access passwords to prevent unauthorized access.

    Why it's wrong here

    Encrypting data and rotating access credentials are security hardening measures, not preservation measures, and they can actively interfere with a litigation hold: changing passwords may deny forensic examiners and counsel access to relevant systems, while encryption without a properly managed key management plan can render evidence inaccessible or alter metadata during the encryption process. Additionally, the duty to preserve does not require restricting authorized access; it requires preventing destruction, alteration, and deletion. Acting unilaterally to lock down systems can itself be challenged as a spoliation tactic.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.