Courseiva

CHFI Incident Response and First Responder Skills Practice Question

During the initial response to a suspected data breach, a first responder discovers a live system with active network connections. The responder needs to preserve evidence while minimizing alteration. Which of the following is the MOST appropriate first step?

⚠ Common exam trap

The CHFI exam often tests the misconception that disconnecting the network or shutting down is the safest first step, but the trap here is that volatile memory is the most critical evidence and must be captured before any action that could alter or destroy it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a memory acquisition tool to capture the contents of RAM.

A is correct because in a live system with active network connections, the most volatile evidence is in RAM (e.g., running processes, network connections, encryption keys). Using a memory acquisition tool (like FTK Imager or WinPmem) captures this volatile data before any other action, preserving evidence that would be lost on shutdown or disconnection. This aligns with the order of volatility (RFC 3227), which prioritizes memory over disk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a memory acquisition tool to capture the contents of RAM.

    Why this is correct

    A memory acquisition tool (e.g., WinPmem, DumpIt, or FTK Imager's memory capture) preserves the volatile data that defines the system's live state: running processes, loaded kernel modules, open network sockets, unencrypted credentials, and memory-resident malware. This is the first step in RFC 3227's volatility order because every subsequent action—including disk imaging, network isolation, or powering off—will alter or destroy these transient artifacts, leaving the investigation without the most probative evidence of the breach.

  • ✗

    Run a full disk imaging tool to capture the hard drive contents.

    Why it's wrong here

    Full disk imaging captures only non-volatile storage, so it misses the dynamic evidence in RAM that is essential for identifying the attack vector, such as active processes, injected DLLs, or inter-process communication. A disk image takes considerable time to complete, during which the live system continues executing and memory changes, and the imaging tool itself may overwrite free disk sectors or cause the OS to swap memory to disk, further contaminating the evidence. Correct protocol is to snapshot memory first, then image the disk.

  • ✗

    Disconnect the network cable to isolate the system from the network.

    Why it's wrong here

    Disconnecting the network cable is a containment response to stop further exfiltration or propagation, but it does nothing to preserve volatile evidence; in fact, the act of running a 'disconnect' command or even physically pulling the cable can trigger application or OS events that modify memory, such as generating network timeout errors or updating connection tables. Because the system remains powered on, processes continue to allocate memory and change the evidence, so network isolation should be deferred until after memory capture.

  • ✗

    Immediately shut down the system by pulling the power cord.

    Why it's wrong here

    Immediately pulling the power cord drops voltage to RAM, and without a fresh power source all dynamic contents are lost within milliseconds—cryptographic keys, process tokens, and malware artifacts are irretrievably gone. It also leaves the file system in an unclean state (potentially corrupting journal or NTFS metadata) and may cause swap files to be stale, while the disk itself remains unchanged but the live evidence is gone. For forensic integrity, a proper memory dump before shutdown is the only acceptable method.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.