CHFI Computer Forensics Fundamentals and Process Practice Question
During a forensic investigation, a first responder notices that a computer is running and suspects that volatile data may be present. According to best practices, what should the responder do to preserve the most volatile data first?
⚠ Common exam trap
Many candidates confuse 'preserving data integrity' with 'avoiding corruption' and choose a graceful shutdown (Option A), not realizing that the shutdown process itself destroys the most volatile evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture the contents of RAM using a forensic tool, then shut down
Volatile data, such as the contents of RAM, is lost when power is removed. The first responder must capture this data using a forensic tool (e.g., FTK Imager, WinPmem, or LiME) before performing a shutdown. This follows the Order of Volatility (RFC 3227), which prioritizes capturing registers, cache, and RAM before any persistent storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a graceful shutdown to avoid data corruption
Why it's wrong here
A graceful shutdown triggers the operating system to flush disk caches, update filesystem metadata, write event logs, and terminate processes — all of which alter stateful evidence on the medium. More importantly, it irrevocably destroys the contents of RAM, which may contain encryption keys, passwords, running processes, network connections, and recently used data. While it avoids some power-loss corruption, it actively overwrites forensic artifacts and violates the exchange principle that evidence must not be changed.
- ✗
Remove the hard drive immediately while the system is running
Why it's wrong here
Removing a hard drive from a running system without first acquiring volatile memory is both an electrical and forensic hazard. Hot-swapping can cause a surge that damages the drive or controller, leading to permanent data loss, and the drive's actuator arm may not be parked, increasing the risk of media damage. Additionally, the system continues writing to disk, logs, and swap during the process, so any data taken is not a pristine snapshot, and critical RAM evidence is lost entirely.
- ✓
Capture the contents of RAM using a forensic tool, then shut down
Why this is correct
This is the correct action because RAM is the most volatile data store and must be captured first per the forensics order of volatility (RFC 3227). A trusted memory acquisition tool — such as FTK Imager, WinPmem, or LiME — creates a bit-for-bit copy of physical memory, which is hashed (e.g., SHA-256) to preserve integrity. After the memory image is securely stored on external media, an administrator-issued shutdown writes only unavoidable OS logs and closes services in a controlled manner, preserving the disk while the critical volatile evidence is already secured.
- ✗
Immediately unplug the power cord to freeze the system state
Why it's wrong here
Immediately unplugging the power cord causes the loss of RAM and CPU cache contents, which are often the most valuable evidence — including memory-resident malware, decrypted data, and active network sessions. It also prevents the operating system from flushing disk write caches, which can leave the filesystem in a dirty or inconsistent state and may trigger journal recovery on the next boot, altering timestamps and file metadata. This 'dead box' approach forfeits live-response evidence and is only acceptable if hostile conditions make a proper memory capture impossible.
Go deeper
Related to this question
Learn chapter
Database Forensics: Investigating Data Breaches
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.