CHFI Computer Forensics Fundamentals and Process Practice Question
During the first response to a computer incident, which of the following actions is MOST critical for preserving evidence?
⚠ Common exam trap
The CHFI exam often tests the misconception that immediately disconnecting power (Option B) is the safest action, but the trap is that this destroys volatile evidence and may cause unintended writes, whereas photographing the scene is the least intrusive and most defensible first step for preserving the physical state of evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Photograph the scene including all visible cables and connections
Photographing the scene, including all visible cables and connections, is the most critical first step in preserving the chain of custody and documenting the exact physical state of the system before any changes occur. This visual record captures port assignments, device connections, and cable orientations that could be altered by subsequent actions, ensuring that the original configuration is preserved for forensic analysis. Without this documentation, later evidence of network topology or peripheral involvement may be lost or disputed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run antivirus software to remove any malware
Why it's wrong here
Running antivirus software on a live system is a dynamic action that alters the very evidence you intend to preserve. The scanner reads files, updates timestamps, touches registry keys, and may quarantine or delete detected items, effectively modifying the media before a forensic image is taken. Additionally, the antivirus process itself creates new artifacts (logs, prefetch files, and memory structures) that contaminate the investigation. The correct first response is to freeze the scene—not to start triage software that changes the filesystem.
- ✗
Disconnect the power to prevent data alteration
Why it's wrong here
Disconnecting power is a hasty action that destroys volatile data—the most time-sensitive and often most valuable evidence in an incident. RAM contains running processes, open network connections, and decrypted data that vanish the instant power is removed. While it is true that powering off prevents further writes to disk, the rule of order of volatility demands that you capture memory and network state first, and only power down as a last resort such as when a system is actively destroying evidence. Therefore, pulling the plug is wrong because it loses volatile evidence, not because it alters disk data.
- ✓
Photograph the scene including all visible cables and connections
Why this is correct
Photographing the scene is a non-invasive, evidence-preserving action that documents the original physical and logical configuration of the system before any other activity occurs. These photographs capture cable connections, external peripherals, hardware settings, and visible on-screen data, which are critical for reconstructing the incident and proving chain of custody. Unlike software execution or power cycling, photography introduces no changes to the system and creates a permanent, timestamped record that is admissible in court. This alone makes it the correct first response in a computer incident.
- ✗
Immediately boot the system to verify it is operational
Why it's wrong here
Booting the system—whether normally or into a recovery mode—is strictly prohibited because the boot process itself rewrites critical evidence. During startup, the OS modifies system logs, registry hives, last-accessed timestamps, and temporary files, and it may launch services that overwrite free space or unallocated clusters. Moreover, simply forcing a system that was in an unknown state to boot can trigger disk-check utilities (chkntfs/fsck) or malware persistence mechanisms that corrupt the original evidence. The act of verifying operability is irrelevant at this stage; the preservation of the system's exact state is paramount.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.