CHFI Storage Forensics and File System Analysis Practice Question
During a forensic investigation, an analyst uses a tool to capture the contents of RAM from a live Linux system. Which tool is specifically designed for this purpose and can acquire memory over a network or via a local kernel module?
⚠ Common exam trap
CHFI often tests the distinction between memory acquisition tools and memory analysis tools, leading candidates to mistakenly select Volatility (a post-acquisition analyzer) instead of LiME (the actual acquisition tool).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LiME
LiME (Linux Memory Extractor) is specifically designed to capture RAM from live Linux systems. It can acquire memory either by loading a kernel module locally or by transmitting the memory dump over a network, making it the correct choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WinPmem
Why it's wrong here
WinPmem targets Windows memory acquisition, not live Linux systems, and lacks the network or loadable kernel module acquisition paths described. It is tempting because it is a genuine memory acquisition tool, and would be correct when capturing RAM from a Windows host.
- ✓
LiME
Why this is correct
LiME is a Linux Memory Extractor loadable kernel module that captures RAM from live Linux systems, supporting acquisition over a network or locally. This matches the stem's requirement for a tool designed specifically for live Linux memory capture.
- ✗
FTK Imager
Why it's wrong here
FTK Imager captures disk images and static forensic snapshots, not live RAM contents; it lacks a kernel module for volatile memory acquisition and cannot operate over a network to dump memory. It is tempting because it is a widely used forensic tool for creating bit-for-bit copies of storage media, and would be correct for acquiring a hard drive image from a suspect system.
- ✗
Volatility
Why it's wrong here
Volatility analyses an existing memory image; it does not acquire RAM from a live Linux host over a network or via a kernel module. It is tempting because it is the best-known memory forensics framework, and would be the right choice for parsing and examining a capture already taken.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.