CHFI Computer Forensics Fundamentals and Process Practice Question
During a forensic examination, the analyst encounters a file that is not automatically readable by forensic tools. The analyst suspects the file contains contraband images. Which of the following is the BEST approach to handle this evidence in accordance with the rules of evidence?
⚠ Common exam trap
EC-Council CHFI often tests the misconception that you can safely open a file on the suspect's computer if you are careful, but the trap is that any direct access to the original evidence violates the forensic principle of non-alteration and can invalidate the entire investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a forensic copy and use a write blocker to access the copy with appropriate software.
Forensic best practices require creating a bit-for-bit forensic copy of the original evidence and using a write blocker to prevent any alteration to the original. The analyst can then use specialized software (e.g., a hex editor, file carving tools, or a viewer that supports the file's raw format) to access the copy and extract contraband images without violating the integrity of the evidence, which is essential for admissibility under rules of evidence such as the Federal Rules of Evidence (FRE) 901.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the file to prevent accidental distribution.
Why it's wrong here
Deleting the file is spoliation of evidence and constitutes intentional destruction of potentially probative material. From a technical standpoint, deletion does not simply remove the content; it also alters filesystem metadata, breaks chain-of-custody records, and may make the evidence unrecoverable or degrade its evidentiary value. Even if the file were later recovered, its authenticity and integrity could be successfully challenged in court, and the analyst could face legal consequences for obstruction or evidence tampering.
- ✓
Create a forensic copy and use a write blocker to access the copy with appropriate software.
Why this is correct
Create a forensic copy by using a hardware write blocker between the original media and the forensic workstation, then acquire a bit-for-bit image (e.g., in E01 or raw format) with a tool like FTK Imager or dd. Verify the integrity of both the original and the copy by recording cryptographic hashes (SHA-256 or MD5) before and after acquisition, ensuring they match. Only after that should you access the copy with appropriate forensic software (e.g., EnCase, Autopsy, X-Ways) to parse the file, leaving the original media untouched and forensically pristine.
- ✗
Ignore the file because it cannot be easily read.
Why it's wrong here
Ignoring the file because it cannot be easily read is a failure to conduct a complete forensic examination and amounts to negligence in preserving and analyzing evidence. Unreadable or unfamiliar files often contain valuable information—such as encrypted containers, proprietary formats, or corrupted data—that can be recovered through file signature identification, hex analysis, or format-specific parsers. The duty of a forensic examiner is to identify, interpret, and document the file's content and metadata using appropriate investigative tools, not to dismiss it based on initial accessibility.
- ✗
Open the file using the original application on the suspect's computer.
Why it's wrong here
Opening the file with the original application directly on the suspect's computer violates forensic best practices and risks altering the evidence. The application may write temporary files, update directory entries, modify last-access timestamps, or execute malicious code that further changes the surrounding system state. Because even a simple read operation can modify metadata on modern filesystems, the integrity of the original evidence would be compromised, making it inadmissible; you should instead examine the file within the forensic copy using a controlled, isolated environment.
Go deeper
Related to this question
Learn chapter
Evidence Handling and Chain of Custody
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
Key term
Data Carving
Data carving is the process of recovering files and data fragments from a storage device without relying on the file system metadata.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.