CHFI Computer Forensics Fundamentals and Process Practice Question
During a forensic investigation, a junior analyst suggests using a software write blocker to image a suspect's hard drive. Which of the following is the PRIMARY concern with relying solely on a software write blocker in a high-stakes legal case?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Software write blockers may be circumvented if the operating system is compromised.
Software write blockers are not as reliable as hardware ones because they rely on the operating system, which can be compromised; hardware write blockers provide physical write protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Software write blockers may be circumvented if the operating system is compromised.
Why this is correct
A software write blocker operates as a kernel driver or userspace filter within the very operating system it is trying to protect. If that OS is compromised—for example, by a rootkit or malicious kernel module—the blocker's I/O filtering can be disabled, bypassed, or spoofed, allowing writes to reach the evidence media unnoticed. This is why hardware write blockers are preferred: they enforce read-only protection at the device/interface level, independent of the state of the host operating system.
- ✗
Software write blockers require additional licensing fees.
Why it's wrong here
While some commercial software write blockers are paid products that may require licensing fees, this is an administrative and procurement matter, not a forensic integrity issue. A forensic investigation's primary concern is preventing any modification to evidence, and cost can be mitigated through budget approvals or by choosing open-source tools. The licensing cost never affects whether the evidence remains pristine, so it is not the critical reason hardware blockers are recommended.
- ✗
Software write blockers are not compatible with all operating systems.
Why it's wrong here
Compatibility with all operating systems is indeed a limitation of software write blockers because they rely on OS-specific driver frameworks, APIs, and file-system stack hooks. However, forensic analysts normally work in controlled lab environments with known OS versions and can select an appropriate tool or use a dedicated forensic workstation, making this a practical inconvenience rather than a fundamental flaw. The decisive issue remains the trustworthiness of the write-blocking mechanism, not the breadth of OS support.
- ✗
Software write blockers are too slow for large drives.
Why it's wrong here
The perceived speed penalty of software write blockers is not the controlling factor in forensic practice, because write blocking is essentially a simple command-filtering operation that does not bottleneck modern SATA, NVMe, or USB interfaces. Even if a particular software blocker introduced measurable overhead, the absolute requirement of preventing writes to evidence outweighs any performance trade-off. Acquisition speed is a secondary operational concern; evidentiary integrity and admissibility take precedence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.