CHFI Computer Forensics Fundamentals and Process Practice Question
During a forensic investigation, the first responder arrives at a scene where a computer is powered on and a user is logged in. Which of the following is the MOST appropriate initial action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network and take a photograph of the screen
Securing the scene and documenting everything is the first priority to preserve evidence and ensure chain of custody. Powering off or accessing the system without proper documentation can lead to evidence spoliation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately power off the computer to prevent data alteration
Why it's wrong here
Abruptly pulling power is not a preservation step; it destroys volatile data held in RAM, including running processes, active network connections, decryption keys, and ephemeral chat content. It also can trigger filesystem journal replay, alter MAC times, and cause unexpected writes from the OS page cache, thereby changing the evidence record. Forensic best practice is to capture a memory image with a dedicated tool before any shutdown.
- ✗
Begin collecting data by copying all files to an external drive
Why it's wrong here
Copying selected files to an external drive before applying write-blocking and forensic imaging violates the first responder's duty to preserve a bit-for-bit acquisition and can update file access times, altering metadata. This approach misses deleted files, unallocated space, and slack space, thereby omitting critical hidden evidence. Moreover, without contemporaneous notes, a written chain of custody, and cryptographic hashes, the resulting data will likely be ruled inadmissible in court.
- ✓
Disconnect the computer from the network and take a photograph of the screen
Why this is correct
Disconnecting the network cable isolates the machine from live remote control, stops exfiltration, and prevents a remote actor from remotely wiping or modifying the evidence. Taking a photograph of the screen before any interaction preserves the visible state of running applications, chat windows, encryption banners, and console output, which would be lost immediately upon shutdown or further user activity. This staged approach follows the order of volatility while simultaneously documenting the live scene.
- ✗
Ask the user to save their work and then shut down normally
Why it's wrong here
Instructing the user to save work and shut down normally causes active, user-driven writes to the file system, registry, event logs, and disk cache, overwriting metadata and potentially destroying memory-resident artifacts such as passwords and open documents. It also provides the user an opportunity to delete, encrypt, or otherwise alter evidence, and a normal shutdown flushes caches and updates last-access timestamps, contaminating the very timeline investigators depend on. First responders must never delegate system interaction to the suspect or any untrained person.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.