Courseiva

CCNA Forensics Lab Questions

9 questions · Forensics Lab topic · All types, answers revealed

1
MCQmedium

A forensic lab manager is setting up a new lab and must decide on the physical security measures. Which of the following is the MOST important to implement first?

A.Construct Faraday cages around the evidence storage area
B.Deploy CCTV cameras covering all entry points
C.Install a gas-based fire suppression system
D.Implement a biometric access control system
AnswerD

Biometric access control authenticates individuals using unique physiological characteristics—such as fingerprints, iris patterns, or facial geometry—making it nearly impossible to lend, steal, or duplicate credentials. This enforces physical access as a preventive control, ensuring only pre-authorized personnel enter evidence storage areas, thereby maintaining chain of custody and legal defensibility. Unlike keys or cards, biometrics provide non-repudiation because each entry attempt is tied to a specific person and can be logged for audit. It directly addresses the foundational risk of unauthorized access, which is the first and most critical security requirement for a forensic lab.

Why this answer

Biometric access control is the most critical first step because it establishes a foundational layer of physical security that authenticates and authorizes personnel before they can access the lab. Without controlling who enters, other measures like CCTV or fire suppression are less effective, as unauthorized individuals could compromise evidence integrity. This aligns with the principle of defense-in-depth, where access control is the primary barrier against tampering or theft.

Exam trap

The trap here is that candidates often prioritize surveillance (CCTV) or evidence preservation (Faraday cages) over the foundational security principle of access control, failing to recognize that without controlling who enters, all other measures are reactive rather than preventive.

How to eliminate wrong answers

Option A is wrong because Faraday cages are specialized for blocking electromagnetic signals (e.g., to prevent remote wiping of mobile devices) and are not a general physical security measure; they should be implemented after basic access controls are in place. Option B is wrong because CCTV cameras are a monitoring/deterrent tool, not a preventive control; they record breaches but do not stop unauthorized access, making them secondary to access control. Option C is wrong because gas-based fire suppression systems protect against fire damage but do not address the immediate threat of unauthorized entry or evidence tampering; they are a safety measure, not a security measure.

2
MCQmedium

A forensic lab in a shared office building must protect evidence against unauthorized physical access, environmental damage, and electromagnetic interference. The lab manager is documenting the physical controls for an accreditation audit. Which control best addresses the risk of an intruder removing a seized hard drive from the evidence room?

A.A locked evidence locker with a keypad entry log and tamper-evident seals on each evidence bag
B.A UPS connected to the forensic workstation to prevent power loss during imaging
C.An antistatic wrist strap worn by the examiner while handling the drive
D.A Faraday bag used to store mobile phones during transport
AnswerA

A locked evidence locker with logged keypad entry and tamper-evident seals directly prevents and detects unauthorized removal of a seized drive. The entry log creates an auditable record of who accessed the evidence room, while the seals reveal any attempt to open an evidence bag after seizure. Together they satisfy the physical security and chain-of-custody expectations for a forensics lab.

Why this answer

The scenario asks for a control against unauthorized physical removal of evidence. Only a locked evidence locker with logged keypad access and tamper-evident seals both restricts entry and provides detection if a bag is opened. The other choices protect power continuity, block wireless signals, or prevent electrostatic damage, none of which stop an intruder from taking a drive.

Exam trap

The trap here is confusing environmental or handling safeguards such as UPS units and wrist straps with actual physical access controls that restrict who can reach the evidence.

3
MCQhard

A forensic lab receives a sealed evidence bag containing a laptop seized during an investigation. The chain-of-custody form shows the bag was sealed at the scene by an officer. Before beginning analysis, the examiner must document the evidence. Which action best preserves the chain of custody at this point?

A.Ask the officer who sealed the bag to re-seal it in the lab before analysis
B.Immediately open the bag and begin imaging to save time
C.Store the bag in the evidence locker and delay documentation until analysis begins
D.Photograph the sealed bag and its seal number, then record the date, time, and examiner name before opening
AnswerD

Photographing the sealed bag and recording the seal number, date, time, and examiner name creates an auditable record of the bag's condition at receipt. This documentation links the seal applied at the scene to the examiner who opens it, preserving continuity. It is the expected first step before any analysis and supports later testimony about evidence integrity.

Why this answer

Chain of custody requires documenting the evidence's condition at every transfer. Photographing the sealed bag, recording the seal number, and logging the date, time, and examiner name before opening establishes an unbroken record from seizure to analysis. Skipping, delaying, or re-sealing without documentation creates gaps that weaken admissibility.

Exam trap

The trap here is treating chain of custody as a formality that can be completed later, when in fact the receipt documentation is the critical link that proves the evidence was not altered.

4
Multi-Selectmedium

A forensics lab is preparing a new acquisition workstation for imaging suspect drives. The lab manager wants to ensure the workstation itself does not introduce evidence contamination or alter suspect media during imaging. Which two practices should be implemented? (Choose two.)

Select 2 answers
A.Install the suspect drive's original operating system on the workstation to match the environment
B.Use a hardware write-blocker between the workstation and the suspect drive
C.Disable the workstation's antivirus to improve imaging speed
D.Verify the acquired image hash against the source drive hash after imaging
E.Connect the suspect drive as the primary boot device to speed up access
AnswersB, D

A hardware write-blocker prevents the workstation from writing to the suspect drive, preserving the original media during imaging. This is a core lab practice to avoid evidence contamination and to ensure the source hash matches the image. Without it, the workstation could modify file system metadata and invalidate the acquisition.

Why this answer

The two practices that directly prevent contamination and alteration are using a hardware write-blocker and verifying the image hash against the source. The write-blocker stops writes to the suspect drive, and the hash comparison proves the image is an exact copy. The other options either modify the suspect drive, introduce unrelated data, or do not address evidence integrity.

Exam trap

The trap here is thinking that faster or more convenient configurations, such as booting from the suspect drive, are acceptable when they actually alter the evidence.

5
MCQeasy

A junior examiner is preparing a forensics lab workstation that will be used to image suspect drives. The lab policy states the workstation must never write to a connected suspect drive. Which practice ensures this requirement is met?

A.Connect the suspect drive through a hardware write-blocker before imaging
B.Enable BitLocker on the suspect drive before connecting it
C.Mount the suspect drive with the read-only attribute set in Windows Disk Management
D.Image the drive over the network using a mapped drive letter
AnswerA

A hardware write-blocker physically intercepts write commands on the interface, so the suspect drive cannot be modified during imaging. This is the standard lab practice for preserving evidence integrity and is expected by CHFI when acquiring suspect media. Using it before imaging ensures the original drive remains unaltered and the hash of the source matches the image.

Why this answer

Imaging suspect media without altering it requires a hardware write-blocker placed between the workstation and the drive. Software attributes, encryption, and network mapping do not guarantee the drive stays unmodified. The write-blocker enforces read-only at the interface level, which is the accepted lab practice for preserving evidence integrity.

Exam trap

The trap here is assuming that a read-only attribute or a mapped network drive is equivalent to a hardware write-blocker, when only the hardware device reliably blocks writes.

6
MCQmedium

A forensic lab is establishing a chain of custody procedure. Which practice is considered best according to CHFI guidelines?

A.Require biometric authentication for all lab personnel
B.Store evidence in a secure room with limited access
C.Use encryption to protect evidence files
D.Document every transfer of evidence with signatures and timestamps
AnswerD

Proper chain-of-custody documentation requires an unbroken chronological record that identifies every individual who had control of the evidence, the exact date and time of each transfer, and the reason for the transfer. Each exchange must be signed by both the releasing and receiving custodians to verify that the evidence was in their possession and was not unaccounted for. This documentation is pivotal in court to demonstrate that the evidence is authentic and has not been substituted, altered, or tampered with. Without signatures and timestamps, a court may deem the evidence inadmissible on the grounds of a broken custody chain.

Why this answer

The chain of custody is fundamentally a legal and procedural requirement to demonstrate the integrity and admissibility of digital evidence. CHFI guidelines emphasize that every transfer of evidence must be meticulously documented with signatures, timestamps, and purpose to create an unbroken audit trail, which is the only practice that directly satisfies the legal standard for evidence handling.

Exam trap

EC-Council often tests the distinction between security controls (like encryption or access restrictions) and procedural documentation (like signatures and timestamps), leading candidates to confuse physical or technical safeguards with the legal requirement for an auditable chain of custody.

How to eliminate wrong answers

Option A is wrong because biometric authentication controls access to the lab but does not document the transfer or handling of evidence, which is the core requirement for chain of custody. Option B is wrong because storing evidence in a secure room with limited access is a physical security measure, not a documentation procedure; it does not create the required audit trail for each transfer. Option C is wrong because encryption protects evidence files from unauthorized access or tampering but does not provide a documented record of who handled the evidence and when, which is essential for chain of custody.

7
MCQeasy

You are a forensic examiner at a corporate security firm. You receive a laptop from the HR department that belonged to a terminated employee. The laptop was used for company business and is suspected of containing unauthorized file-sharing software. The laptop is running Windows 10 with BitLocker drive encryption enabled. Before shutdown, the employee was logged into the system. HR claims the laptop was shut down properly and then handed over within an hour. You are asked to acquire a forensic image of the hard drive for analysis. However, when you boot the laptop, you are prompted for the BitLocker recovery key. HR does not have the key, and the employee refuses to cooperate. The laptop also has a TPM chip. Which of the following is the most appropriate course of action to acquire the data?

A.Contact IT to obtain the BitLocker recovery key from Active Directory.
B.Perform a cold boot attack to extract the BitLocker key from memory.
C.Boot from a Linux live USB and use tools to bypass BitLocker.
D.Boot the laptop normally and let BitLocker unlock the drive using the TPM.
AnswerA

This is the correct first step because corporate BitLocker recovery keys are often backed up to Active Directory. Retrieving it is the most straightforward method to access the drive.

Why this answer

The laptop was shut down properly, but the boot-time recovery key prompt indicates that the TPM did not automatically release the BitLocker key. In an enterprise environment, the most appropriate first action is to obtain the BitLocker recovery key from Active Directory, where BitLocker recovery information is commonly escrowed. Cold boot attacks and Linux live USB bypass tools are not reliable or authorized first steps, and booting normally again would not resolve the failed TPM unlock and could alter evidence.

Exam trap

EC-Council often tests the misconception that a properly shut-down system with TPM will always unlock automatically via TPM. However, the question explicitly states that booting prompts for a recovery key, indicating TPM unlock failed. The trap is to assume D is still correct, but the correct first step is to retrieve the recovery key from Active Directory.

How to eliminate wrong answers

Option A is wrong because contacting IT to obtain the BitLocker recovery key from Active Directory is a valid step only if the key was escrowed, but the question states HR does not have the key and the employee refuses to cooperate; however, the most appropriate immediate action is to boot normally first, as the TPM will unlock the drive without needing the recovery key. Option B is wrong because a cold boot attack is a specialized technique used to extract memory contents from a system that was recently running, but here the laptop was shut down properly an hour ago, so the memory contents (including any BitLocker key remnants) are long gone; this attack is impractical and not the most appropriate course. Option C is wrong because booting from a Linux live USB and using tools to bypass BitLocker is not feasible against a fully encrypted drive with TPM-bound keys; BitLocker with TPM protection cannot be bypassed by simply booting an alternate OS, as the TPM will not release the key to an untrusted boot environment.

8
MCQhard

A forensic lab is designing a network architecture to ensure the integrity of evidence during acquisition. What is the most critical design consideration?

A.Deploy multiple forensic workstations to parallelize tasks
B.Use a segmented network to isolate forensic tools
C.Encrypt all data in transit over the network
D.Implement hardware write-blockers on all acquisition stations
AnswerD

A hardware write-blocker is inserted between the source drive and the forensic workstation, electrically or logically blocking write commands at the SATA/USB/IDE interface, so the operating system and forensic software cannot modify the original media under any circumstances. This is the direct technical control that preserves bit-for-bit integrity and enables valid cryptographic hash matching before and after acquisition. Using a write-blocker on every acquisition station is considered best practice in digital forensics and is required for standardized forensic imaging workflows.

Why this answer

Hardware write-blockers are the most critical design consideration because they physically prevent any write operations to the source drive at the ATA/SCSI command level, ensuring that the evidence remains bit-for-bit unchanged during acquisition. Without a hardware write-blocker, even a single read operation from a forensic workstation could inadvertently modify metadata (e.g., last access timestamps) or trigger anti-forensic mechanisms, compromising the integrity of the evidence and its admissibility in court.

Exam trap

The trap here is that candidates often confuse network security measures (segmentation, encryption) with evidence integrity controls, failing to recognize that the most critical design consideration is preventing any write access to the source media at the hardware level during acquisition.

How to eliminate wrong answers

Option A is wrong because deploying multiple forensic workstations to parallelize tasks improves throughput but does not address the fundamental requirement of preserving evidence integrity; it can even introduce chain-of-custody issues if not properly managed. Option B is wrong because using a segmented network to isolate forensic tools enhances security and prevents unauthorized access, but it does not prevent write operations to the source drive during acquisition, which is the primary integrity concern. Option C is wrong because encrypting data in transit over the network protects confidentiality and integrity during transfer, but it does not prevent the acquisition station from writing to the source drive; the evidence could be altered before encryption even occurs.

9
Multi-Selecthard

Which TWO of the following are essential components of a computer forensics lab according to CHFI best practices?

Select 2 answers
A.Server farm for data processing
B.Evidence storage area with controlled access
C.Public-facing website for case management
D.Coffee machine for staff convenience
E.Forensic workstation with specialized software
AnswersB, E

Evidence storage area with controlled access is essential to a forensic lab because it establishes a physically secure, restricted environment where seized media can be preserved, inventoried, and protected from tampering, environmental damage, or unauthorized access. This directly supports the chain of custody and evidentiary integrity that courts require for admissibility, and is a core component per forensic laboratory best-practice standards. Without such an area, the entire examination process loses its evidentiary foundation.

Why this answer

Option B is correct because CHFI best practices require a physically secure evidence storage area with controlled access to preserve the chain of custody and prevent tampering, theft, or contamination of digital evidence. Option E is correct because a forensic workstation loaded with specialized tools (e.g., EnCase, FTK, write blockers, and hashing utilities) is the core hardware/software platform needed to acquire, image, and analyze evidence without altering it. The other options are not essential lab components: a server farm (A) is unnecessary for typical forensic analysis, a public-facing website (C) would actually create security and confidentiality risks, and a coffee machine (D) is merely a convenience item with no forensic function.

Exam trap

EC-Council often tests the distinction between 'nice-to-have' items (like coffee machines) and mandatory security components (like controlled-access evidence storage), leading candidates to select convenience over critical infrastructure.

Ready to test yourself?

Try a timed practice session using only Forensics Lab questions.