Courseiva

CHFI · domain

Computer Forensics Fundamentals and Process

This domain covers the foundational concepts and legal framework of computer forensics as tested on the CHFI exam: evidence handling, chain of custody, write blockers, expert witness testimony, and the overall investigative process. Questions are scenario-based, asking you to identify the primary purpose, best definition, or most important qualification among plausible-sounding alternatives.

128 questions32 easy62 medium34 hard

Focused practice

Practice Computer Forensics Fundamentals and Process questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Computer Forensics Fundamentals and Process

You must be able to explain why evidence integrity, documented custody, and admissible testimony matter in each phase of an investigation. The single most important thing: a write blocker prevents any modification to the source drive, preserving it for court.

Purpose of a hardware or software write blocker in preserving evidence integrity during acquisition

Definition and documentation requirements of the chain of custody for digital evidence

Qualifications a court weighs when accepting an investigator as an expert witness

Primary goal of computer forensics: identifying, preserving, analyzing, and presenting digital evidence

Watch out for

Common Computer Forensics Fundamentals and Process exam traps

  • ▸Confusing a write blocker's purpose (prevent modification) with encryption or hashing tools that verify integrity after acquisition.
  • ▸Treating chain of custody as only the initial seizure record, ignoring every transfer, access, and storage event afterward.
  • ▸Assuming technical skill alone qualifies an expert witness, when the court also weighs experience, training, and relevance to the case.

Question index

All Computer Forensics Fundamentals and Process questions (128)

Click any question to see the full explanation, or start a practice session above.

1

An organization receives a legal hold notice regarding a pending lawsuit. The IT department is instructed to preserve all relevant electronically stored information (ESI). Which of the following actions must be taken FIRST?

Hard
2

Which THREE of the following are steps in the forensic investigation process? (Select three.)

Hard
3

A security analyst arrives at a suspected computer crime scene. The computer is on and a user is logged in. The analyst needs to preserve volatile data. According to first responder duties, what should the analyst do FIRST?

Medium
4

A first responder arrives at a scene where a computer is suspected to contain evidence of fraud. The computer is turned on and a file is open. Which of the following actions should the responder AVOID?

Medium
5

A forensic examiner needs to verify the integrity of a forensic image after acquisition. Which of the following methods is the MOST reliable for ensuring the image has not been altered?

Medium
6

During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. What is the primary purpose of using a hardware write blocker?

Medium
7

A first responder arrives at a suspected data breach scene. The system is powered on and a user is logged in. Which of the following actions should the responder take FIRST to preserve volatile data?

Medium
8

Which TWO of the following are essential steps that a first responder should take when arriving at a digital crime scene? (Select TWO)

Medium
9

During a forensic examination of a Windows system, the investigator finds a file named 'notes.txt' that contains a list of passwords. The file's last modified timestamp is before the incident date, but its last accessed timestamp is during the incident. Which type of evidence is this file considered?

Medium
10

A forensic investigator is required to testify in court about the findings of a digital investigation. Which of the following roles does the investigator fulfill?

Medium
11

Which of the following tools is specifically designed for forensic imaging and can create compressed, segmented, or E01 format images?

Medium
12

An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT administrator is instructed to preserve all relevant electronic records. Which of the following actions is MOST consistent with proper legal hold implementation?

Hard
13

A forensic examiner is presented with evidence that a suspect's computer was used to commit a fraud. The defense argues that the evidence was obtained without a warrant. Which US Constitutional Amendment is MOST relevant to this argument?

Hard
14

A forensic analyst is creating a forensic image of a suspect's hard drive using a write blocker. Which of the following BEST describes the purpose of using a hardware write blocker?

Medium
15

During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. Which of the following is the PRIMARY reason for using a write blocker?

Medium
16

During a forensic investigation, an analyst creates a forensic image using `dcfldd` with the command: `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=10M`. What is the purpose of the `hashwindow` parameter?

Medium
17

A first responder arrives at a crime scene where a computer is running. According to standard forensic procedure, what should the responder do FIRST?

Easy
18

A forensic investigator is documenting evidence for a case. What is the PRIMARY purpose of maintaining an unbroken chain of custody for digital evidence?

Medium
19

A first responder arrives at a scene where a computer is turned on and a user is logged in. What is the FIRST action the responder should take to preserve volatile evidence?

Easy
20

What is the primary goal of the chain of custody in a digital forensic investigation?

Easy
21

Which THREE of the following are best practices for a first responder when arriving at a computer crime scene?

Hard
22

Which TWO of the following are essential components of a proper chain of custody documentation? (Select TWO.)

Medium
23

During a forensic investigation, an analyst acquires a hard drive using a hardware write blocker. Which of the following is the PRIMARY reason for using a hardware write blocker?

Medium
24

In the context of e-discovery, which THREE of the following are key steps in the Electronic Discovery Reference Model (EDRM)? (Select THREE)

Hard
25

During a forensic examination, an analyst uses the command 'dd if=/dev/sda of=/mnt/evidence/image.dd bs=4096 conv=noerror,sync'. What is the primary purpose of the 'conv=noerror,sync' option in this context?

Hard
26

Which of the following is the PRIMARY purpose of using a write blocker in computer forensics?

Easy
27

According to Locard's exchange principle, which of the following is MOST relevant to digital forensics?

Easy
28

Which of the following is the BEST definition of computer forensics?

Easy
29

During an investigation, an analyst uses `dd if=/dev/sdb of=evidence.img bs=4k conv=noerror,sync`. What is the purpose of the `conv=noerror,sync` option?

Hard
30

An organization in the UK suspects an employee of data theft. The IT manager wants to search the employee's company-issued laptop without consent. Which law primarily governs this action?

Hard
31

An investigator needs to testify in court as an expert witness. Which of the following qualifications is MOST important for the court to accept their testimony?

Medium
32

In a UK-based investigation, which legal framework governs the search and seizure of digital evidence?

Medium
33

A company's legal department issues a legal hold notice for electronically stored information (ESI) related to a pending lawsuit. The IT department is tasked with preserving data. Which of the following actions is MOST likely to violate the legal hold requirements?

Hard
34

A forensic analyst is examining a hard drive that was imaged using a software write blocker. Which of the following is a potential disadvantage of using a software write blocker compared to a hardware write blocker?

Hard
35

In the context of e-discovery, what does the 'best evidence rule' require regarding digital documents?

Hard
36

An analyst runs 'dcfldd if=/dev/sdb of=/evidence/disk.dd hash=sha256 hashlog=/evidence/hash.log' on a Linux system. What is the primary advantage of using dcfldd over plain dd for forensic imaging?

Hard
37

After collecting digital evidence from a suspect's computer, the forensic examiner creates a forensic image using FTK Imager. The examiner then computes the MD5 hash of the original drive and the image file. Which of the following BEST describes the purpose of this hashing?

Medium
38

A forensic examiner needs to acquire an image of a suspect's laptop hard drive. The laptop is running, and the examiner wants to capture volatile data first. According to best practices, which order of steps should the examiner follow?

Medium
39

Locard's exchange principle in digital forensics states that:

Easy
40

Which of the following principles states that when two objects come into contact, there is a transfer of material between them?

Easy
41

A security analyst responds to a suspected data breach. The analyst documents the scene, photographs the computer, and labels the cables. Which phase of the forensic investigation process is being performed?

Medium
42

During a forensic investigation, an analyst creates a bit-for-bit copy of a suspect's hard drive using the 'dd' command with the following parameters: dd if=/dev/sda of=/evidence/image.dd bs=4k conv=noerror,sync. What is the purpose of 'conv=noerror,sync'?

Medium
43

Which of the following BEST defines the chain of custody in digital forensics?

Easy
44

Which principle states that every contact leaves a trace?

Easy
45

An investigator creates a forensic image using dcfldd with the following command: dcfldd if=/dev/sdb of=image.dd hash=sha256 hashwindow=10M hashlog=hash.txt. What is the effect of the 'hashwindow=10M' parameter?

Hard
46

During a forensic investigation, the first responder arrives at a scene where a computer is powered on and a user is logged in. Which of the following is the MOST appropriate initial action?

Easy
47

A forensic analyst needs to collect evidence from a running Windows system without altering the system state. Which tool should they use to acquire volatile memory?

Medium
48

In a corporate investigation, legal counsel issues a litigation hold to preserve electronically stored information (ESI) relevant to a lawsuit. Which of the following is the BEST description of a litigation hold?

Medium
49

What is the primary goal of computer forensics?

Easy
50

During a forensic examination, an analyst runs the following command: 'dd if=/dev/sda of=/mnt/evidence/image.dd bs=4k conv=noerror,sync'. The source drive has bad sectors. What is the effect of the 'conv=noerror,sync' option?

Hard
51

What is the primary purpose of maintaining a chain of custody during a forensic investigation?

Easy
52

A forensic analyst is testifying as an expert witness in court. The opposing counsel challenges the analyst's testimony based on the Frye standard. What does the Frye standard require for scientific evidence to be admissible?

Medium
53

Which of the following BEST describes the chain of custody in digital forensics?

Easy
54

A first responder arrives at a suspected intrusion scene. A desktop computer is powered on and logged in. The user claims they saw suspicious files being copied to a USB drive. Which of the following should the first responder do FIRST?

Medium
55

Which TWO of the following are essential components of chain of custody documentation?

Medium
56

What is the PRIMARY purpose of a chain of custody document in a forensic investigation?

Easy
57

An analyst performs forensic imaging using the command: dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt bs=4096 conv=noerror,sync. What is the PRIMARY purpose of the 'hash=sha256' and 'hashlog=hash.txt' parameters?

Hard
58

A forensic investigator uses the 'dd' command to create a forensic image. The original drive has a SHA-256 hash of a1b2c3... and the image produces the same hash. Which rule of evidence does this satisfy?

Medium
59

In the context of the UK Police and Criminal Evidence Act (PACE), which of the following is a key requirement for the admissibility of digital evidence?

Medium
60

An investigator needs to acquire data from a suspect's hard drive without altering any data. Which tool is MOST appropriate to ensure write-blocking at the hardware level?

Medium
61

An organization receives a legal hold notice regarding pending litigation. The IT department is instructed to preserve all relevant electronically stored information. What is the primary action the IT department should take?

Medium
62

Which of the following BEST describes Locard's exchange principle as applied to digital forensics?

Easy
63

Which of the following is a key requirement for digital evidence to be considered admissible in court?

Medium
64

Locard's exchange principle is fundamental to forensic science. How does this principle apply to computer forensics?

Easy
65

During an investigation, a forensic analyst must preserve a hard drive that is part of a RAID array. Which of the following is the MOST appropriate method to preserve the evidence?

Medium
66

During a forensic investigation, a first responder notices that a computer is running and suspects that volatile data may be present. According to best practices, what should the responder do to preserve the most volatile data first?

Hard
67

During a forensic investigation, an analyst uses the following command: dd if=/dev/sda of=/mnt/evidence/image.dd bs=4096 conv=noerror,sync. What is the effect of the conv=noerror,sync option?

Hard
68

In the context of the US Fourth Amendment, what is typically required for law enforcement to seize a computer for forensic examination?

Easy
69

A first responder arrives at a crime scene where a computer is powered on and displaying a desktop. According to best practices, which of the following actions should the responder take FIRST?

Easy
70

A first responder arrives at a crime scene where a computer is running. Which THREE actions should the first responder take to preserve volatile evidence?

Hard
71

During an internal investigation, an employee is suspected of leaking sensitive data. The security team finds that the employee's computer has been turned off. Which of the following evidence types would be LOST due to the system being powered off?

Hard
72

A forensic examiner uses a hardware write blocker when imaging a suspect's hard drive. What is the primary function of a hardware write blocker?

Medium
73

A company receives a legal hold notice regarding a lawsuit. What immediate action should the company take to comply?

Medium
74

A security analyst notices that a log file on a Linux server shows repeated failed SSH login attempts from an external IP address, but no successful login from that IP. However, the /var/log/auth.log file has been recently truncated. Which type of evidence is the truncated log file?

Medium
75

Which of the following is the BEST description of Locard's exchange principle as applied to digital forensics?

Medium
76

Which TWO of the following hashing algorithms are commonly used to verify the integrity of forensic images? (Choose two.)

Easy
77

During a forensic investigation, a lawyer objects to the admissibility of a log file on the grounds that it is hearsay. Which of the following is the BEST argument to overcome this objection?

Medium
78

A forensic examiner is preparing to testify as an expert witness. Which THREE of the following qualities are essential for the examiner's testimony to be admissible under the Daubert standard? (Select THREE)

Medium
79

During a forensic investigation, the examiner uses a write blocker to connect the suspect drive to the forensic workstation. What is the PRIMARY purpose of using a write blocker?

Medium
80

In a UK-based investigation, the police seize a computer without a warrant. The suspect's lawyer argues that the evidence is inadmissible because it violates which law?

Hard
81

During a forensic investigation, an analyst uses a tool to create a bit-for-bit copy of a hard drive while ensuring the original is not modified. Which of the following is a hardware write blocker that can be used for this purpose?

Medium
82

Which of the following is an example of Locard's Exchange Principle as applied to digital forensics?

Medium
83

During an e-discovery process, a legal hold is issued. What is the PRIMARY purpose of a legal hold?

Medium
84

Which of the following BEST describes the purpose of a legal hold in e-discovery?

Medium
85

During a forensic investigation, a junior analyst suggests using a software write blocker to image a suspect's hard drive. Which of the following is the PRIMARY concern with relying solely on a software write blocker in a high-stakes legal case?

Medium
86

A forensic analyst creates a forensic image of a hard drive using the dd command: dd if=/dev/sda of=/evidence/image.dd bs=4096 conv=noerror,sync. What is the purpose of the 'conv=noerror,sync' option?

Medium
87

A legal hold is issued by an organization's legal department. What is the primary purpose of a legal hold?

Medium
88

Which TWO of the following are valid justifications for a first responder to power off a computer at a crime scene? (Select TWO)

Medium
89

According to Locard's exchange principle, which of the following is TRUE in a digital forensic context?

Easy
90

A forensic examiner has acquired a disk image using FTK Imager and needs to ensure the image is an exact duplicate of the original drive. Which THREE of the following methods can be used to verify integrity? (Select THREE)

Hard
91

Under the US Fourth Amendment, when is a warrant generally NOT required for a computer search and seizure?

Easy
92

Which hashing algorithm is commonly used in forensic imaging to verify the integrity of evidence and is considered more secure than MD5?

Medium
93

Which of the following is the BEST definition of Locard's exchange principle in computer forensics?

Easy
94

Which TWO of the following are valid reasons for using a hardware write blocker over a software write blocker? (Select two.)

Medium
95

Which TWO of the following are valid reasons for a first responder to power off a computer system at a crime scene? (Select TWO)

Medium
96

A first responder arrives at a crime scene where a computer is turned on. What should the responder do FIRST?

Easy
97

During a forensic investigation, the analyst needs to verify the integrity of a forensic image. The analyst originally computed MD5 and SHA-1 hashes of the source drive. Which action BEST ensures the image has not been altered?

Hard
98

During a forensic investigation, the analyst needs to create a forensic image of a hard drive that also hashes the data during acquisition. Which command-line tool would be MOST appropriate for this task?

Medium
99

Which THREE of the following are essential steps in the digital forensics investigation process? (Select three.)

Hard
100

A forensic analyst needs to create a forensic image of a suspect's hard drive using FTK Imager. Which of the following image formats is MOST appropriate for maintaining evidence integrity and allowing compression?

Medium
101

An expert witness is preparing to testify in a computer forensics case. Which of the following is a key requirement for the expert's testimony to be admissible under the Daubert standard?

Medium
102

During a forensic examination, an analyst runs `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=1G` on a suspect drive. What is the PRIMARY advantage of using `hashwindow=1G` over a single hash at the end?

Hard
103

An investigator seizes a computer that was involved in a crime. The suspect claims that the evidence was planted. Which forensic principle best helps to refute this claim by demonstrating that the evidence could only have been left by the suspect?

Hard
104

In a UK-based investigation, law enforcement officers seize a computer without a warrant. The suspect argues the seizure violated his rights under the Police and Criminal Evidence Act 1984 (PACE). Which of the following is a key consideration under PACE regarding the admissibility of the seized evidence?

Hard
105

A security analyst discovers unauthorized access to a server. The incident response team decides to preserve evidence. Which of the following actions is MOST critical to ensure the admissibility of evidence in court?

Hard
106

According to the US Fourth Amendment, which of the following THREE conditions generally allow law enforcement to search and seize digital evidence without a warrant? (Select THREE)

Hard
107

A security analyst arrives at a crime scene where a computer is turned on and the screen shows a document. What is the FIRST action the analyst should take according to forensic best practices?

Easy
108

A forensic examiner is testifying in a U.S. court about a disk image acquired from a suspect's computer. The defense attorney argues that the image is not admissible because it is a copy, not the original. The examiner explains that the image was created using a write-blocker and verified with SHA-256 hashes. Which legal principle supports the admissibility of the disk image?

Medium
109

An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT department is instructed to preserve all relevant electronic data. Which of the following actions should be taken FIRST to comply with the legal hold?

Medium
110

Which type of evidence is based on information that is not directly from an eyewitness but is reported by someone else?

Easy
111

Which TWO of the following are examples of circumstantial evidence in a digital forensics investigation? (Select TWO)

Easy
112

A first responder arrives at a crime scene involving a suspected hacking incident. The suspect's computer is powered on and logged in. The responder needs to decide the first action to preserve evidence. According to the order of volatility, which of the following should be collected first?

Easy
113

A forensic analyst is preparing to acquire an image from a suspect's hard drive. The analyst connects the drive to a write blocker, then uses FTK Imager to create a forensic image. Which hashing algorithm is commonly used by FTK Imager to verify image integrity?

Medium
114

A forensic examiner is preparing to acquire a forensic image of a running Windows 10 laptop suspected of containing evidence of intellectual property theft. The examiner must capture volatile data that could be lost if the system is shut down. Which TWO of the following actions should the examiner take to preserve volatile evidence before imaging? (Choose two.)

Hard
115

Which TWO of the following are types of write blockers used in forensic imaging? (Select two.)

Easy
116

Which type of evidence is a witness's statement that they saw someone log into a computer?

Medium
117

A forensic examiner needs to create a bit-for-bit copy of a suspect's hard drive for analysis. Which tool is specifically designed for this purpose and can also verify integrity using hashing?

Medium
118

Which TWO of the following are common hashing algorithms used to verify the integrity of forensic images? (Select two.)

Easy
119

Which TWO of the following are requirements for evidence to be admissible in court? (Select two.)

Medium
120

During the first response to a computer incident, which of the following actions is MOST critical for preserving evidence?

Easy
121

A forensic analyst is preparing to testify as an expert witness in court. Which of the following characteristics is MOST essential for the court to accept the analyst's testimony?

Hard
122

During a forensic examination, an analyst uses the command 'dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt'. What is the primary purpose of including 'hash=sha256' in this command?

Hard
123

Which THREE of the following correctly describe the rules of evidence as applied to digital forensics? (Select three.)

Hard
124

A forensic analyst is examining a hard drive that was seized from a suspect's home. The analyst uses FTK Imager to create a forensic image. After imaging, the analyst computes the MD5 hash of the image and compares it to the hash computed at the scene. The hashes match. What does this confirm?

Medium
125

Which US Constitutional amendment primarily governs the legality of searching and seizing digital devices?

Easy
126

A forensic investigator uses FTK Imager to create a forensic image of a suspect's laptop. The acquisition generates both an E01 file and a corresponding hash file. Which statement accurately describes the integrity verification process in FTK Imager?

Hard
127

A forensic analyst is testifying in court as an expert witness. What is the PRIMARY role of an expert witness in digital forensics?

Medium
128

During a forensic examination, the analyst encounters a file that is not automatically readable by forensic tools. The analyst suspects the file contains contraband images. Which of the following is the BEST approach to handle this evidence in accordance with the rules of evidence?

Medium

Frequently asked questions

What does the Computer Forensics Fundamentals and Process domain cover on the CHFI exam?
You must be able to explain why evidence integrity, documented custody, and admissible testimony matter in each phase of an investigation. The single most important thing: a write blocker prevents any modification to the source drive, preserving it for court.
How many questions are in this domain?
This page lists all 128 Computer Forensics Fundamentals and Process questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Computer Forensics Fundamentals and Process questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-chfi EC-CHFI chfi fundamentals process Practice Questions