CHFI Computer Forensics Fundamentals and Process Practice Question
During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. What is the primary purpose of using a hardware write blocker?
⚠ Common exam trap
Candidates often confuse the purpose of a write blocker with other forensic tools or features, such as hashing or compression, which are separate software functions, not hardware-level protections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To prevent the operating system from writing to the source drive
A hardware write blocker physically intercepts the write commands from the forensic workstation to the suspect drive, ensuring that no data can be altered on the source drive during acquisition. This preserves the evidentiary integrity of the original media, which is a foundational requirement in digital forensics to maintain a chain of custody and admissibility in court.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To prevent the operating system from writing to the source drive
Why this is correct
A hardware write blocker is an inline forensic bridge that sits between the source drive and the host system, filtering every ATA/SCSI command. It permits read requests to reach the drive while silently discarding or blocking write commands, so the operating system cannot modify file metadata, timestamps, directory entries, or any other data. This read-only enforcement at the physical interface level is the fundamental legal and technical guarantee of evidence preservation during acquisition.
- ✗
To speed up the data transfer rate during imaging
Why it's wrong here
The write blocker's purpose is solely to block writes and pass reads through; it contains no mechanism to speed up data transfer. In fact, any extra hardware in the signal path can add a negligible amount of latency, though this is far outweighed by the source drive's own read speed and the host interface's throughput. Imaging speed is determined by the forensic imaging tool, the drive's transfer rate, and the interface (e.g., SATA, USB, FireWire), none of which are improved by the write blocker.
- ✗
To compress the forensic image to save storage space
Why it's wrong here
A write blocker operates at the physical command layer and has no awareness of file systems, streams, or data content, so it cannot perform compression. When a forensic image is compressed, the compression algorithm runs in software within the acquisition tool—such as FTK Imager, Guymager, or dc3dd—producing formats like E01, AFF, or compressed raw. The write blocker simply relays raw sector data unchanged, making compression entirely outside its function.
- ✗
To automatically hash the drive contents for integrity verification
Why it's wrong here
Hashing is a cryptographic computation performed by forensic acquisition software, not by a write blocker. A hardware write blocker is anelectrical/interface-level gatekeeper with no firmware for calculating MD5, SHA-1, or SHA-256; it only controls which commands pass to the drive. The imaging tool reads the drive through the blocker and computes the hash value, which is later used to verify that the acquired image matches the source—so hashing is a verification step, not a write-blocking feature.
Go deeper
Related to this question
Learn chapter
Evidence Handling and Chain of Custody
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.