CHFI · domain
Computer Forensics Fundamentals and Process
This domain covers the foundational concepts and legal framework of computer forensics as tested on the CHFI exam: evidence handling, chain of custody, write blockers, expert witness testimony, and the overall investigative process. Questions are scenario-based, asking you to identify the primary purpose, best definition, or most important qualification among plausible-sounding alternatives.
Focused practice
Practice Computer Forensics Fundamentals and Process questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Computer Forensics Fundamentals and Process
You must be able to explain why evidence integrity, documented custody, and admissible testimony matter in each phase of an investigation. The single most important thing: a write blocker prevents any modification to the source drive, preserving it for court.
Purpose of a hardware or software write blocker in preserving evidence integrity during acquisition
Definition and documentation requirements of the chain of custody for digital evidence
Qualifications a court weighs when accepting an investigator as an expert witness
Primary goal of computer forensics: identifying, preserving, analyzing, and presenting digital evidence
Watch out for
Common Computer Forensics Fundamentals and Process exam traps
- ▸Confusing a write blocker's purpose (prevent modification) with encryption or hashing tools that verify integrity after acquisition.
- ▸Treating chain of custody as only the initial seizure record, ignoring every transfer, access, and storage event afterward.
- ▸Assuming technical skill alone qualifies an expert witness, when the court also weighs experience, training, and relevance to the case.
Question index
All Computer Forensics Fundamentals and Process questions (128)
Click any question to see the full explanation, or start a practice session above.
An organization receives a legal hold notice regarding a pending lawsuit. The IT department is instructed to preserve all relevant electronically stored information (ESI). Which of the following actions must be taken FIRST?
Hard2Which THREE of the following are steps in the forensic investigation process? (Select three.)
Hard3A security analyst arrives at a suspected computer crime scene. The computer is on and a user is logged in. The analyst needs to preserve volatile data. According to first responder duties, what should the analyst do FIRST?
Medium4A first responder arrives at a scene where a computer is suspected to contain evidence of fraud. The computer is turned on and a file is open. Which of the following actions should the responder AVOID?
Medium5A forensic examiner needs to verify the integrity of a forensic image after acquisition. Which of the following methods is the MOST reliable for ensuring the image has not been altered?
Medium6During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. What is the primary purpose of using a hardware write blocker?
Medium7A first responder arrives at a suspected data breach scene. The system is powered on and a user is logged in. Which of the following actions should the responder take FIRST to preserve volatile data?
Medium8Which TWO of the following are essential steps that a first responder should take when arriving at a digital crime scene? (Select TWO)
Medium9During a forensic examination of a Windows system, the investigator finds a file named 'notes.txt' that contains a list of passwords. The file's last modified timestamp is before the incident date, but its last accessed timestamp is during the incident. Which type of evidence is this file considered?
Medium10A forensic investigator is required to testify in court about the findings of a digital investigation. Which of the following roles does the investigator fulfill?
Medium11Which of the following tools is specifically designed for forensic imaging and can create compressed, segmented, or E01 format images?
Medium12An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT administrator is instructed to preserve all relevant electronic records. Which of the following actions is MOST consistent with proper legal hold implementation?
Hard13A forensic examiner is presented with evidence that a suspect's computer was used to commit a fraud. The defense argues that the evidence was obtained without a warrant. Which US Constitutional Amendment is MOST relevant to this argument?
Hard14A forensic analyst is creating a forensic image of a suspect's hard drive using a write blocker. Which of the following BEST describes the purpose of using a hardware write blocker?
Medium15During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. Which of the following is the PRIMARY reason for using a write blocker?
Medium16During a forensic investigation, an analyst creates a forensic image using `dcfldd` with the command: `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=10M`. What is the purpose of the `hashwindow` parameter?
Medium17A first responder arrives at a crime scene where a computer is running. According to standard forensic procedure, what should the responder do FIRST?
Easy18A forensic investigator is documenting evidence for a case. What is the PRIMARY purpose of maintaining an unbroken chain of custody for digital evidence?
Medium19A first responder arrives at a scene where a computer is turned on and a user is logged in. What is the FIRST action the responder should take to preserve volatile evidence?
Easy20What is the primary goal of the chain of custody in a digital forensic investigation?
Easy21Which THREE of the following are best practices for a first responder when arriving at a computer crime scene?
Hard22Which TWO of the following are essential components of a proper chain of custody documentation? (Select TWO.)
Medium23During a forensic investigation, an analyst acquires a hard drive using a hardware write blocker. Which of the following is the PRIMARY reason for using a hardware write blocker?
Medium24In the context of e-discovery, which THREE of the following are key steps in the Electronic Discovery Reference Model (EDRM)? (Select THREE)
Hard25During a forensic examination, an analyst uses the command 'dd if=/dev/sda of=/mnt/evidence/image.dd bs=4096 conv=noerror,sync'. What is the primary purpose of the 'conv=noerror,sync' option in this context?
Hard26Which of the following is the PRIMARY purpose of using a write blocker in computer forensics?
Easy27According to Locard's exchange principle, which of the following is MOST relevant to digital forensics?
Easy28Which of the following is the BEST definition of computer forensics?
Easy29During an investigation, an analyst uses `dd if=/dev/sdb of=evidence.img bs=4k conv=noerror,sync`. What is the purpose of the `conv=noerror,sync` option?
Hard30An organization in the UK suspects an employee of data theft. The IT manager wants to search the employee's company-issued laptop without consent. Which law primarily governs this action?
Hard31An investigator needs to testify in court as an expert witness. Which of the following qualifications is MOST important for the court to accept their testimony?
Medium32In a UK-based investigation, which legal framework governs the search and seizure of digital evidence?
Medium33A company's legal department issues a legal hold notice for electronically stored information (ESI) related to a pending lawsuit. The IT department is tasked with preserving data. Which of the following actions is MOST likely to violate the legal hold requirements?
Hard34A forensic analyst is examining a hard drive that was imaged using a software write blocker. Which of the following is a potential disadvantage of using a software write blocker compared to a hardware write blocker?
Hard35In the context of e-discovery, what does the 'best evidence rule' require regarding digital documents?
Hard36An analyst runs 'dcfldd if=/dev/sdb of=/evidence/disk.dd hash=sha256 hashlog=/evidence/hash.log' on a Linux system. What is the primary advantage of using dcfldd over plain dd for forensic imaging?
Hard37After collecting digital evidence from a suspect's computer, the forensic examiner creates a forensic image using FTK Imager. The examiner then computes the MD5 hash of the original drive and the image file. Which of the following BEST describes the purpose of this hashing?
Medium38A forensic examiner needs to acquire an image of a suspect's laptop hard drive. The laptop is running, and the examiner wants to capture volatile data first. According to best practices, which order of steps should the examiner follow?
Medium39Locard's exchange principle in digital forensics states that:
Easy40Which of the following principles states that when two objects come into contact, there is a transfer of material between them?
Easy41A security analyst responds to a suspected data breach. The analyst documents the scene, photographs the computer, and labels the cables. Which phase of the forensic investigation process is being performed?
Medium42During a forensic investigation, an analyst creates a bit-for-bit copy of a suspect's hard drive using the 'dd' command with the following parameters: dd if=/dev/sda of=/evidence/image.dd bs=4k conv=noerror,sync. What is the purpose of 'conv=noerror,sync'?
Medium43Which of the following BEST defines the chain of custody in digital forensics?
Easy44Which principle states that every contact leaves a trace?
Easy45An investigator creates a forensic image using dcfldd with the following command: dcfldd if=/dev/sdb of=image.dd hash=sha256 hashwindow=10M hashlog=hash.txt. What is the effect of the 'hashwindow=10M' parameter?
Hard46During a forensic investigation, the first responder arrives at a scene where a computer is powered on and a user is logged in. Which of the following is the MOST appropriate initial action?
Easy47A forensic analyst needs to collect evidence from a running Windows system without altering the system state. Which tool should they use to acquire volatile memory?
Medium48In a corporate investigation, legal counsel issues a litigation hold to preserve electronically stored information (ESI) relevant to a lawsuit. Which of the following is the BEST description of a litigation hold?
Medium49What is the primary goal of computer forensics?
Easy50During a forensic examination, an analyst runs the following command: 'dd if=/dev/sda of=/mnt/evidence/image.dd bs=4k conv=noerror,sync'. The source drive has bad sectors. What is the effect of the 'conv=noerror,sync' option?
Hard51What is the primary purpose of maintaining a chain of custody during a forensic investigation?
Easy52A forensic analyst is testifying as an expert witness in court. The opposing counsel challenges the analyst's testimony based on the Frye standard. What does the Frye standard require for scientific evidence to be admissible?
Medium53Which of the following BEST describes the chain of custody in digital forensics?
Easy54A first responder arrives at a suspected intrusion scene. A desktop computer is powered on and logged in. The user claims they saw suspicious files being copied to a USB drive. Which of the following should the first responder do FIRST?
Medium55Which TWO of the following are essential components of chain of custody documentation?
Medium56What is the PRIMARY purpose of a chain of custody document in a forensic investigation?
Easy57An analyst performs forensic imaging using the command: dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt bs=4096 conv=noerror,sync. What is the PRIMARY purpose of the 'hash=sha256' and 'hashlog=hash.txt' parameters?
Hard58A forensic investigator uses the 'dd' command to create a forensic image. The original drive has a SHA-256 hash of a1b2c3... and the image produces the same hash. Which rule of evidence does this satisfy?
Medium59In the context of the UK Police and Criminal Evidence Act (PACE), which of the following is a key requirement for the admissibility of digital evidence?
Medium60An investigator needs to acquire data from a suspect's hard drive without altering any data. Which tool is MOST appropriate to ensure write-blocking at the hardware level?
Medium61An organization receives a legal hold notice regarding pending litigation. The IT department is instructed to preserve all relevant electronically stored information. What is the primary action the IT department should take?
Medium62Which of the following BEST describes Locard's exchange principle as applied to digital forensics?
Easy63Which of the following is a key requirement for digital evidence to be considered admissible in court?
Medium64Locard's exchange principle is fundamental to forensic science. How does this principle apply to computer forensics?
Easy65During an investigation, a forensic analyst must preserve a hard drive that is part of a RAID array. Which of the following is the MOST appropriate method to preserve the evidence?
Medium66During a forensic investigation, a first responder notices that a computer is running and suspects that volatile data may be present. According to best practices, what should the responder do to preserve the most volatile data first?
Hard67During a forensic investigation, an analyst uses the following command: dd if=/dev/sda of=/mnt/evidence/image.dd bs=4096 conv=noerror,sync. What is the effect of the conv=noerror,sync option?
Hard68In the context of the US Fourth Amendment, what is typically required for law enforcement to seize a computer for forensic examination?
Easy69A first responder arrives at a crime scene where a computer is powered on and displaying a desktop. According to best practices, which of the following actions should the responder take FIRST?
Easy70A first responder arrives at a crime scene where a computer is running. Which THREE actions should the first responder take to preserve volatile evidence?
Hard71During an internal investigation, an employee is suspected of leaking sensitive data. The security team finds that the employee's computer has been turned off. Which of the following evidence types would be LOST due to the system being powered off?
Hard72A forensic examiner uses a hardware write blocker when imaging a suspect's hard drive. What is the primary function of a hardware write blocker?
Medium73A company receives a legal hold notice regarding a lawsuit. What immediate action should the company take to comply?
Medium74A security analyst notices that a log file on a Linux server shows repeated failed SSH login attempts from an external IP address, but no successful login from that IP. However, the /var/log/auth.log file has been recently truncated. Which type of evidence is the truncated log file?
Medium75Which of the following is the BEST description of Locard's exchange principle as applied to digital forensics?
Medium76Which TWO of the following hashing algorithms are commonly used to verify the integrity of forensic images? (Choose two.)
Easy77During a forensic investigation, a lawyer objects to the admissibility of a log file on the grounds that it is hearsay. Which of the following is the BEST argument to overcome this objection?
Medium78A forensic examiner is preparing to testify as an expert witness. Which THREE of the following qualities are essential for the examiner's testimony to be admissible under the Daubert standard? (Select THREE)
Medium79During a forensic investigation, the examiner uses a write blocker to connect the suspect drive to the forensic workstation. What is the PRIMARY purpose of using a write blocker?
Medium80In a UK-based investigation, the police seize a computer without a warrant. The suspect's lawyer argues that the evidence is inadmissible because it violates which law?
Hard81During a forensic investigation, an analyst uses a tool to create a bit-for-bit copy of a hard drive while ensuring the original is not modified. Which of the following is a hardware write blocker that can be used for this purpose?
Medium82Which of the following is an example of Locard's Exchange Principle as applied to digital forensics?
Medium83During an e-discovery process, a legal hold is issued. What is the PRIMARY purpose of a legal hold?
Medium84Which of the following BEST describes the purpose of a legal hold in e-discovery?
Medium85During a forensic investigation, a junior analyst suggests using a software write blocker to image a suspect's hard drive. Which of the following is the PRIMARY concern with relying solely on a software write blocker in a high-stakes legal case?
Medium86A forensic analyst creates a forensic image of a hard drive using the dd command: dd if=/dev/sda of=/evidence/image.dd bs=4096 conv=noerror,sync. What is the purpose of the 'conv=noerror,sync' option?
Medium87A legal hold is issued by an organization's legal department. What is the primary purpose of a legal hold?
Medium88Which TWO of the following are valid justifications for a first responder to power off a computer at a crime scene? (Select TWO)
Medium89According to Locard's exchange principle, which of the following is TRUE in a digital forensic context?
Easy90A forensic examiner has acquired a disk image using FTK Imager and needs to ensure the image is an exact duplicate of the original drive. Which THREE of the following methods can be used to verify integrity? (Select THREE)
Hard91Under the US Fourth Amendment, when is a warrant generally NOT required for a computer search and seizure?
Easy92Which hashing algorithm is commonly used in forensic imaging to verify the integrity of evidence and is considered more secure than MD5?
Medium93Which of the following is the BEST definition of Locard's exchange principle in computer forensics?
Easy94Which TWO of the following are valid reasons for using a hardware write blocker over a software write blocker? (Select two.)
Medium95Which TWO of the following are valid reasons for a first responder to power off a computer system at a crime scene? (Select TWO)
Medium96A first responder arrives at a crime scene where a computer is turned on. What should the responder do FIRST?
Easy97During a forensic investigation, the analyst needs to verify the integrity of a forensic image. The analyst originally computed MD5 and SHA-1 hashes of the source drive. Which action BEST ensures the image has not been altered?
Hard98During a forensic investigation, the analyst needs to create a forensic image of a hard drive that also hashes the data during acquisition. Which command-line tool would be MOST appropriate for this task?
Medium99Which THREE of the following are essential steps in the digital forensics investigation process? (Select three.)
Hard100A forensic analyst needs to create a forensic image of a suspect's hard drive using FTK Imager. Which of the following image formats is MOST appropriate for maintaining evidence integrity and allowing compression?
Medium101An expert witness is preparing to testify in a computer forensics case. Which of the following is a key requirement for the expert's testimony to be admissible under the Daubert standard?
Medium102During a forensic examination, an analyst runs `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=1G` on a suspect drive. What is the PRIMARY advantage of using `hashwindow=1G` over a single hash at the end?
Hard103An investigator seizes a computer that was involved in a crime. The suspect claims that the evidence was planted. Which forensic principle best helps to refute this claim by demonstrating that the evidence could only have been left by the suspect?
Hard104In a UK-based investigation, law enforcement officers seize a computer without a warrant. The suspect argues the seizure violated his rights under the Police and Criminal Evidence Act 1984 (PACE). Which of the following is a key consideration under PACE regarding the admissibility of the seized evidence?
Hard105A security analyst discovers unauthorized access to a server. The incident response team decides to preserve evidence. Which of the following actions is MOST critical to ensure the admissibility of evidence in court?
Hard106According to the US Fourth Amendment, which of the following THREE conditions generally allow law enforcement to search and seize digital evidence without a warrant? (Select THREE)
Hard107A security analyst arrives at a crime scene where a computer is turned on and the screen shows a document. What is the FIRST action the analyst should take according to forensic best practices?
Easy108A forensic examiner is testifying in a U.S. court about a disk image acquired from a suspect's computer. The defense attorney argues that the image is not admissible because it is a copy, not the original. The examiner explains that the image was created using a write-blocker and verified with SHA-256 hashes. Which legal principle supports the admissibility of the disk image?
Medium109An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT department is instructed to preserve all relevant electronic data. Which of the following actions should be taken FIRST to comply with the legal hold?
Medium110Which type of evidence is based on information that is not directly from an eyewitness but is reported by someone else?
Easy111Which TWO of the following are examples of circumstantial evidence in a digital forensics investigation? (Select TWO)
Easy112A first responder arrives at a crime scene involving a suspected hacking incident. The suspect's computer is powered on and logged in. The responder needs to decide the first action to preserve evidence. According to the order of volatility, which of the following should be collected first?
Easy113A forensic analyst is preparing to acquire an image from a suspect's hard drive. The analyst connects the drive to a write blocker, then uses FTK Imager to create a forensic image. Which hashing algorithm is commonly used by FTK Imager to verify image integrity?
Medium114A forensic examiner is preparing to acquire a forensic image of a running Windows 10 laptop suspected of containing evidence of intellectual property theft. The examiner must capture volatile data that could be lost if the system is shut down. Which TWO of the following actions should the examiner take to preserve volatile evidence before imaging? (Choose two.)
Hard115Which TWO of the following are types of write blockers used in forensic imaging? (Select two.)
Easy116Which type of evidence is a witness's statement that they saw someone log into a computer?
Medium117A forensic examiner needs to create a bit-for-bit copy of a suspect's hard drive for analysis. Which tool is specifically designed for this purpose and can also verify integrity using hashing?
Medium118Which TWO of the following are common hashing algorithms used to verify the integrity of forensic images? (Select two.)
Easy119Which TWO of the following are requirements for evidence to be admissible in court? (Select two.)
Medium120During the first response to a computer incident, which of the following actions is MOST critical for preserving evidence?
Easy121A forensic analyst is preparing to testify as an expert witness in court. Which of the following characteristics is MOST essential for the court to accept the analyst's testimony?
Hard122During a forensic examination, an analyst uses the command 'dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt'. What is the primary purpose of including 'hash=sha256' in this command?
Hard123Which THREE of the following correctly describe the rules of evidence as applied to digital forensics? (Select three.)
Hard124A forensic analyst is examining a hard drive that was seized from a suspect's home. The analyst uses FTK Imager to create a forensic image. After imaging, the analyst computes the MD5 hash of the image and compares it to the hash computed at the scene. The hashes match. What does this confirm?
Medium125Which US Constitutional amendment primarily governs the legality of searching and seizing digital devices?
Easy126A forensic investigator uses FTK Imager to create a forensic image of a suspect's laptop. The acquisition generates both an E01 file and a corresponding hash file. Which statement accurately describes the integrity verification process in FTK Imager?
Hard127A forensic analyst is testifying in court as an expert witness. What is the PRIMARY role of an expert witness in digital forensics?
Medium128During a forensic examination, the analyst encounters a file that is not automatically readable by forensic tools. The analyst suspects the file contains contraband images. Which of the following is the BEST approach to handle this evidence in accordance with the rules of evidence?
MediumOther domains
All CHFI exam domains
Frequently asked questions
- What does the Computer Forensics Fundamentals and Process domain cover on the CHFI exam?
- You must be able to explain why evidence integrity, documented custody, and admissible testimony matter in each phase of an investigation. The single most important thing: a write blocker prevents any modification to the source drive, preserving it for court.
- How many questions are in this domain?
- This page lists all 128 Computer Forensics Fundamentals and Process questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Computer Forensics Fundamentals and Process questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.