Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

During a forensic acquisition of a suspect's SSD, the analyst notices that the drive supports TRIM. Which of the following is the most important consideration when acquiring the drive to preserve deleted data?

⚠ Common exam trap

EC-CHFI often tests the misconception that TRIM is beneficial for forensics or that formatting helps, when in fact TRIM is destructive to deleted data and must be prevented by immediate acquisition with a write-blocker.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a hardware write-blocker and acquire the drive immediately to minimize TRIM interference

SSDs with TRIM support automatically issue commands to erase deallocated blocks, making deleted data unrecoverable. Using a hardware write-blocker and acquiring the drive immediately minimizes the time the drive is powered on, reducing the chance that the operating system or the SSD's garbage collection will issue TRIM commands that permanently wipe deleted data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a full format of the SSD before acquisition to clear any TRIM-related issues

    Why it's wrong here

    Performing a full format of the SSD before acquisition is catastrophic because the format process itself issues TRIM commands across the entire logical block address space, causing the drive's controller to permanently erase flash cells that may contain deleted files or residual data. Additionally, a full format overwrites file system structures and user data, destroying the very evidence forensic examiners need to recover. Rather than clearing TRIM-related issues, it actively creates an unrecoverable state.

  • ✓

    Use a hardware write-blocker and acquire the drive immediately to minimize TRIM interference

    Why this is correct

    Using a hardware write-blocker and acquiring the drive immediately is the only correct approach because the write-blocker physically prevents any host-initiated T commands, including TRIM, from reaching the SSD, preserving the current state. The urgency minimizes the opportunity for the SSD's internal garbage collection to run during idle time, which could erase blocks that still contain recoverable data. A forensic image captures both allocated and unallocated space, and acquiring without delay ensures maximum data retention before the controller reclaims any stale blocks.

  • ✗

    Enable TRIM in the forensic tool to ensure the drive is optimized before imaging

    Why it's wrong here

    Enabling TRIM in the forensic tool would actively issue an ATA TRIM command to the SSD, which forcibly invalidates and erases logical blocks that have been marked for deletion, permanently destroying potential evidence such as remnants of deleted files in unallocated space. Forensic tools must never send TRIM because it tells the drive to delete data, and once erased, the NAND cells cannot be reconstructed or recovered by any forensic method. The correct practice is to disable TRIM and use write-blocking to prevent any destructive commands from being issued during imaging.

  • ✗

    The SSD should be powered on for several hours to allow TRIM to complete before imaging

    Why it's wrong here

    Leaving the SSD powered on for several hours is counterproductive because modern SSDs aggressively perform background garbage collection during idle periods, reading valid pages and erasing entire blocks that contain invalidated or deleted data, which destroys recoverable artifacts. Furthermore, the SSD's controller may also process queued TRIM commands or similar maintenance operations while powered, clearing unallocated space that could contain crucial evidence. The drive should be imaged as quickly as possible after acquisition, not deliberately left powered on to allow these self-destructive processes to proceed.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.