Courseiva

CHFI · domain

Evidence Acquisition and Duplication

Evidence Acquisition and Duplication covers creating a forensically sound bit-for-bit copy of suspect media and proving it is unchanged. CHFI tests this through scenario items: choosing the right acquisition method for live versus powered-off systems, using tools like dd, FTK Imager, and EnCase, applying write blockers, and validating integrity with MD5/SHA hashes.

11 questions3 easy3 medium5 hard

Focused practice

Practice Evidence Acquisition and Duplication questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Evidence Acquisition and Duplication

A candidate must be able to acquire a forensically sound image of a disk or live system and prove its integrity. The single most important thing is matching the hash of the original evidence against the acquired image, and knowing that a mismatch points to acquisition errors, not necessarily tampering.

Selecting static vs live acquisition based on system state and volatility

Using dd, dcfldd, FTK Imager, and EnCase to create disk images

Applying hardware and software write blockers to prevent evidence alteration

Verifying image integrity by comparing MD5/SHA-1 hashes of source and image

Watch out for

Common Evidence Acquisition and Duplication exam traps

  • ▸Assuming a hash mismatch always means tampering, when I/O errors or bad sectors during acquisition are the more likely cause
  • ▸Imaging a powered-on system without first capturing volatile data such as RAM, network connections, and running processes
  • ▸Connecting the suspect drive directly to the forensic workstation without a write blocker, altering timestamps and metadata

Question index

All Evidence Acquisition and Duplication questions (11)

Click any question to see the full explanation, or start a practice session above.

1

A forensic investigator is preparing to acquire a USB flash drive that is suspected to contain evidence of intellectual property theft. The investigator needs to ensure that the acquisition process does not alter any data on the flash drive. Which of the following should the investigator use?

Easy
2

A forensic examiner needs to acquire a hard drive that is part of a RAID 5 array. The RAID controller is unavailable. What is the best approach to acquire the data?

Easy
3

During a forensic acquisition, you notice that the target drive has bad sectors. What is the best approach to acquire the drive?

Medium
4

You are a forensic investigator responding to a data breach at a financial institution. The compromised server is a Windows Server 2019 running a custom trading application. The server is still powered on and connected to the production network. The incident response team has instructed you to acquire forensic evidence while minimizing downtime. The server has 2 TB of storage with 500 GB used. You have a forensic workstation with a write-blocker and an empty 2 TB external drive. The server's RAM is 64 GB. You need to acquire both volatile data (RAM) and a forensic image of the disk. However, the legal team requires a verified bit-for-bit copy with cryptographic hash verification. Additionally, the server's performance is critical; acquiring RAM via network is not feasible due to bandwidth constraints. Which of the following is the best course of action?

Hard
5

You are a forensic investigator responding to a suspected data breach at a financial institution. The incident response team has isolated a Windows 10 workstation used by a former employee. The system is still powered on, and the login screen is displayed. Your task is to acquire forensic evidence in a defensible manner. The following actions are available: A. Immediately pull the power cord to perform a cold acquisition of the hard drive. B. Capture volatile data (RAM, network connections, running processes) using a trusted tool on a USB drive, then shut down normally and remove the hard drive for imaging. C. Boot the system from a forensic live CD and create a forensic image of the hard drive while the system is running. D. Use the built-in Windows backup to create a system image to an external drive. Which action is the most appropriate first step in this scenario?

Hard
6

You are imaging a suspect's hard drive using a write blocker and dd command. After imaging, you verify the hash of the original drive and the image file. The original drive hash is SHA1: A1B2C3D4E5..., and the image hash is SHA1: F6G7H8I9J0... What is the most likely cause of the mismatch?

Hard
7

The command used to acquire a disk image resulted in an I/O error. What is the most likely cause?

Medium
8

Which of the following is the primary purpose of using a hardware write blocker during disk acquisition?

Easy
9

An investigator must acquire a 2 TB USB 3.0 external hard drive as evidence in a fraud case. The drive contains a single NTFS volume with 500 GB of allocated data. The investigator needs to create a forensic image that captures all allocated and unallocated space, and the acquisition must be completed as quickly as possible while maintaining evidential integrity. Which acquisition method should the investigator use?

Medium
10

Based on the acquisition log, what can be concluded about the integrity of the acquired image?

Hard
11

A forensic examiner is acquiring a running Linux server that is part of a live incident response. The server hosts a critical database and cannot be taken offline. The examiner needs to capture volatile data in a forensically sound manner. Which TWO of the following actions should the examiner perform? (Choose two.)

Hard

Frequently asked questions

What does the Evidence Acquisition and Duplication domain cover on the CHFI exam?
A candidate must be able to acquire a forensically sound image of a disk or live system and prove its integrity. The single most important thing is matching the hash of the original evidence against the acquired image, and knowing that a mismatch points to acquisition errors, not necessarily tampering.
How many questions are in this domain?
This page lists all 11 Evidence Acquisition and Duplication questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Evidence Acquisition and Duplication questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-chfi EC-CHFI evidence acquisition Practice Questions