CHFI Computer Forensics Fundamentals and Process Practice Question
During a forensic investigation, the examiner uses a write blocker to connect the suspect drive to the forensic workstation. What is the PRIMARY purpose of using a write blocker?
⚠ Common exam trap
The CHFI exam often tests the misconception that write blockers are used to prevent the examiner from accidentally writing to the drive, but the real trap is that candidates confuse the purpose with data protection (encryption) or performance enhancement, rather than understanding it is strictly about preserving the original state by blocking OS-level writes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To prevent the operating system from writing data to the evidence drive
The primary purpose of a write blocker is to intercept and block any write commands from the operating system to the evidence drive, ensuring that the original data remains unaltered (bit-for-bit identical) during acquisition. This maintains the forensic integrity of the evidence, which is critical for admissibility in legal proceedings. Without a write blocker, the OS could automatically write metadata, logs, or temporary files to the drive, contaminating the evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To speed up the data acquisition process
Why it's wrong here
A write blocker is a hardware or software filter placed between the evidence drive and the acquisition workstation, and every I/O command is intercepted and evaluated. Because the device sits in the data path and must translate commands between interfaces (e.g., SATA to USB), it introduces latency that can slightly slow throughput compared to a direct connection. Its goal is never performance; imaging speed is bounded by the drive’s read transfer rate and the interface bandwidth. Thus, using a write blocker to speed up acquisition misunderstands the tool’s forensic integrity purpose.
- ✗
To encrypt the data on the evidence drive
Why it's wrong here
Encryption is a cryptographic transformation that converts plaintext data into ciphertext using an algorithm and a key; a write blocker performs no such operation. A write blocker’s only role is to filter commands to a storage device, passing read operations and discarding write operations, leaving the underlying data bytes completely untouched. It neither alters, obscures, nor protects the data’s content, and it has no key management capability. The claim confuses two distinct concepts: preserving evidence integrity (write protection) and ensuring confidentiality (encryption).
- ✓
To prevent the operating system from writing data to the evidence drive
Why this is correct
When an evidence drive is attached to a forensic workstation, the operating system may automatically write metadata, update access timestamps, mount a volume, or modify system log entries. A write blocker intercepts write commands at the drive interface (such as ATA, SATA, or USB) and returns a fabricated success status without ever issuing the write to the physical disk. This ensures that the original drive remains bit-for-bit unchanged, which is essential for later hash verification of the forensic image. By preventing OS writes, the blocker preserves the evidentiary integrity of the source medium.
- ✗
To allow the evidence drive to be used as a boot device
Why it's wrong here
Booting an operating system from an evidence drive inevitably generates write activity, including page file creation, event logging, and registry hive updates, which would taint the evidence; a write blocker is specifically designed to prevent such writes. In fact, many operating systems will fail to boot normally when all write commands are blocked, because initialization routines require persistent storage writes. A hardware write blocker is an inline bridge, not a boot controller—it does not provide firmware or BIOS support for booting. Therefore, using a write blocker to enable booting is both physically and logically contrary to its forensic purpose.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.