Courseiva
Incident Response and First Responder SkillseasyMultiple ChoiceObjective-mapped

Photograph the Screen: First Step for a First Responder

A first responder arrives at a scene where a computer is powered on and a user is logged in. An incident is suspected. What should the responder do FIRST?

Quick Answer

The correct first step is to photograph the screen. This is because volatile evidence—such as open applications, active network connections, and the logged-in user’s current activity—can be lost the moment the system is powered down or altered. By capturing a photograph of the screen, the first responder preserves a baseline of the system’s state, ensuring critical data is documented before any forensic acquisition begins. On the CHFI exam, this scenario tests your understanding of evidence preservation priorities under the Computer Hacking Forensic Investigator framework; a common trap is to immediately pull the plug or log off, which destroys volatile data. Remember the memory tip: “Photo first, power later”—the screen’s snapshot is your first line of defense against data loss.

⚠ Common exam trap

EC-Council often tests the misconception that immediate memory capture or power-off is the correct first step, but the trap here is that the first responder must first document the volatile state of the screen to preserve evidence that can be lost the instant any action is taken.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Photograph the screen to document the current state.

The first priority at a live incident scene is to preserve volatile evidence. Photographing the screen captures the current state of the system, including open applications, network connections, and user activity, which can be lost if the system is altered or powered down. This documentation provides a baseline for the investigation and ensures that critical volatile data is recorded before any forensic acquisition begins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Begin capturing a memory dump using a forensic tool.

    Why it's wrong here

    Documentation should precede active collection.

  • Power off the computer immediately to preserve the disk.

    Why it's wrong here

    Powering off destroys volatile evidence in memory.

  • Photograph the screen to document the current state.

    Why this is correct

    Documentation of the live state is critical before any collection.

  • Ask the user to log off so the system can be imaged.

    Why it's wrong here

    Logging off alters system state and may lose evidence.

About these practice questions

This CHFI question is part of Courseiva's 205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO actions are essential for a first responder when securing an incident scene involving a compromised server? (Select exactly two.)

hard
  • A.Run antivirus scans to identify and remove any malware present.
  • B.Document the system’s date and time settings for accurate timeline reconstruction.
  • C.Photograph the physical setup, including all cables and peripheral connections.
  • D.Reboot the system into safe mode to prevent further damage.
  • E.Connect an external hard drive to create a backup of important files.

Why B: The system's date and time settings are critical for establishing a reliable timeline of events during forensic analysis. The first responder must document these settings (e.g., from the BIOS or operating system) before any changes occur, as they directly affect the timestamps of file system metadata (MAC times) and log entries. Without this baseline, correlating events across multiple sources becomes unreliable, potentially invalidating the entire investigation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.