CHFI · domain
Computer Forensics Investigation Process
This domain covers the forensic investigation process: securing a scene, preserving volatile and non-volatile evidence, maintaining chain of custody, preparing a forensic workstation with write blockers, and acquiring images. Questions present realistic scenarios where you must choose the correct sequence of actions or interpret tool output on Windows and Linux systems.
Focused practice
Practice Computer Forensics Investigation Process questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Computer Forensics Investigation Process
You must be able to order evidence preservation steps correctly, validate a write blocker, and acquire a forensic image without altering the source. The single most important thing is to preserve volatile data first and maintain chain of custody throughout.
Order of volatility and correct evidence collection sequence for Windows and Linux systems
Use of hardware write blockers and validation before imaging USB or hard drives
Forensic imaging commands such as dd, dcfldd, FTK Imager, and EnCase
BitLocker recovery key usage and post-acquisition decryption of encrypted drives
Watch out for
Common Computer Forensics Investigation Process exam traps
- ▸Shutting down or rebooting a system before capturing volatile data, destroying RAM, network connections, and running processes.
- ▸Connecting a suspect drive without a verified write blocker, risking accidental modification of evidence.
- ▸Misinterpreting e2fsck errors on a Windows system when the tool is meant for Linux ext2/3/4 filesystems.
Question index
All Computer Forensics Investigation Process questions (5)
Click any question to see the full explanation, or start a practice session above.
During a forensic investigation, an analyst discovers that the suspect's hard drive was encrypted using BitLocker. The analyst has obtained the recovery key. Which of the following is the best next step to ensure data integrity?
Easy2A CHFI analyst is called to investigate a suspected data breach. The IT team has already shut down the server. Which of the following is the most appropriate order of actions to preserve evidence?
Medium3A CHFI analyst is called to investigate a suspected insider threat. The suspect's laptop is turned on and logged in. The analyst needs to capture volatile data before shutting it down. Which of the following should the analyst capture first?
Easy4An analyst executed the commands shown in the exhibit on a Windows system to prepare a forensic image for analysis. What is the most likely reason for the error message from e2fsck?
Medium5A CHFI analyst is preparing a forensic workstation to image a suspect's USB flash drive. The analyst needs to ensure that the write-blocker is functioning correctly before connecting the drive. Which of the following is the most appropriate method to verify that the write-blocker is preventing write operations?
MediumOther domains
All CHFI exam domains
Frequently asked questions
- What does the Computer Forensics Investigation Process domain cover on the CHFI exam?
- You must be able to order evidence preservation steps correctly, validate a write blocker, and acquire a forensic image without altering the source. The single most important thing is to preserve volatile data first and maintain chain of custody throughout.
- How many questions are in this domain?
- This page lists all 5 Computer Forensics Investigation Process questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Computer Forensics Investigation Process questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.