Courseiva

CHFI · domain

Computer Forensics Investigation Process

This domain covers the forensic investigation process: securing a scene, preserving volatile and non-volatile evidence, maintaining chain of custody, preparing a forensic workstation with write blockers, and acquiring images. Questions present realistic scenarios where you must choose the correct sequence of actions or interpret tool output on Windows and Linux systems.

5 questions2 easy3 medium

Focused practice

Practice Computer Forensics Investigation Process questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Computer Forensics Investigation Process

You must be able to order evidence preservation steps correctly, validate a write blocker, and acquire a forensic image without altering the source. The single most important thing is to preserve volatile data first and maintain chain of custody throughout.

Order of volatility and correct evidence collection sequence for Windows and Linux systems

Use of hardware write blockers and validation before imaging USB or hard drives

Forensic imaging commands such as dd, dcfldd, FTK Imager, and EnCase

BitLocker recovery key usage and post-acquisition decryption of encrypted drives

Watch out for

Common Computer Forensics Investigation Process exam traps

  • ▸Shutting down or rebooting a system before capturing volatile data, destroying RAM, network connections, and running processes.
  • ▸Connecting a suspect drive without a verified write blocker, risking accidental modification of evidence.
  • ▸Misinterpreting e2fsck errors on a Windows system when the tool is meant for Linux ext2/3/4 filesystems.

Frequently asked questions

What does the Computer Forensics Investigation Process domain cover on the CHFI exam?
You must be able to order evidence preservation steps correctly, validate a write blocker, and acquire a forensic image without altering the source. The single most important thing is to preserve volatile data first and maintain chain of custody throughout.
How many questions are in this domain?
This page lists all 5 Computer Forensics Investigation Process questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Computer Forensics Investigation Process questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-chfi EC-CHFI forensics investigation Practice Questions