Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

During the first response to a computer incident, which of the following actions is MOST critical for preserving evidence?

⚠ Common exam trap

The CHFI exam often tests the misconception that immediately disconnecting power (Option B) is the safest action, but the trap is that this destroys volatile evidence and may cause unintended writes, whereas photographing the scene is the least intrusive and most defensible first step for preserving the physical state of evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Photograph the scene including all visible cables and connections

Photographing the scene, including all visible cables and connections, is the most critical first step in preserving the chain of custody and documenting the exact physical state of the system before any changes occur. This visual record captures port assignments, device connections, and cable orientations that could be altered by subsequent actions, ensuring that the original configuration is preserved for forensic analysis. Without this documentation, later evidence of network topology or peripheral involvement may be lost or disputed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run antivirus software to remove any malware

    Why it's wrong here

    Running antivirus software on a live system is a dynamic action that alters the very evidence you intend to preserve. The scanner reads files, updates timestamps, touches registry keys, and may quarantine or delete detected items, effectively modifying the media before a forensic image is taken. Additionally, the antivirus process itself creates new artifacts (logs, prefetch files, and memory structures) that contaminate the investigation. The correct first response is to freeze the scene—not to start triage software that changes the filesystem.

  • ✗

    Disconnect the power to prevent data alteration

    Why it's wrong here

    Disconnecting power is a hasty action that destroys volatile data—the most time-sensitive and often most valuable evidence in an incident. RAM contains running processes, open network connections, and decrypted data that vanish the instant power is removed. While it is true that powering off prevents further writes to disk, the rule of order of volatility demands that you capture memory and network state first, and only power down as a last resort such as when a system is actively destroying evidence. Therefore, pulling the plug is wrong because it loses volatile evidence, not because it alters disk data.

  • ✓

    Photograph the scene including all visible cables and connections

    Why this is correct

    Photographing the scene is a non-invasive, evidence-preserving action that documents the original physical and logical configuration of the system before any other activity occurs. These photographs capture cable connections, external peripherals, hardware settings, and visible on-screen data, which are critical for reconstructing the incident and proving chain of custody. Unlike software execution or power cycling, photography introduces no changes to the system and creates a permanent, timestamped record that is admissible in court. This alone makes it the correct first response in a computer incident.

  • ✗

    Immediately boot the system to verify it is operational

    Why it's wrong here

    Booting the system—whether normally or into a recovery mode—is strictly prohibited because the boot process itself rewrites critical evidence. During startup, the OS modifies system logs, registry hives, last-accessed timestamps, and temporary files, and it may launch services that overwrite free space or unallocated clusters. Moreover, simply forcing a system that was in an unknown state to boot can trigger disk-check utilities (chkntfs/fsck) or malware persistence mechanisms that corrupt the original evidence. The act of verifying operability is irrelevant at this stage; the preservation of the system's exact state is paramount.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.