Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

Which THREE of the following are essential steps in the digital forensics investigation process? (Select three.)

⚠ Common exam trap

EC-Council often tests the distinction between the forensic process steps and unrelated technical concepts like encryption or destruction, so candidates may mistakenly select 'Encryption' because they confuse a common obstacle with a required phase, or 'Destruction' because they think evidence must be destroyed after analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Examination

The digital forensics investigation process follows a defined sequence of phases, and Collection (D) is essential because it is the phase where potentially relevant data is identified, preserved, and acquired from sources such as disks, memory, and logs using write-blockers and hashing to maintain integrity. Examination (A) is essential because it is where the collected data is filtered, extracted, and reduced to identify only the information relevant to the case, using forensic tools and techniques. Analysis (B) is essential because it is where the examined data is interpreted to answer the investigative questions, establish timelines, attribute actions, and draw conclusions supported by the evidence. Encryption (C) is not a forensic process phase; it is a data-protection technique that may be encountered as an obstacle during examination, not a required step. Destruction (E) is not part of the investigation process either, since evidence must be preserved and retained per legal and chain-of-custody requirements rather than destroyed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Examination

    Why this is correct

    Examination is the forensic phase where collected data is systematically processed to locate and extract potentially relevant information, such as deleted files, hidden partitions, and unallocated space. Examiners use specialized software, keyword filters, file-signature analysis, and write-blockers to ensure the original evidence is not altered. This step is essential because it converts raw acquired data into a focused set of artifacts that can later be interpreted.

  • ✓

    Analysis

    Why this is correct

    Analysis is the interpretive phase that follows examination, where the examiner evaluates the extracted artifacts, correlates timestamps, metadata, and system logs, and reconstructs the sequence of events to answer investigative questions. It applies logical reasoning, link analysis, and hypothesis testing to determine the meaning and significance of the evidence. This step is essential because it turns extracted data into conclusions that support or refute allegations.

  • ✗

    Encryption

    Why it's wrong here

    Encryption is a data-protection mechanism that encodes information so that only authorized parties with the correct key can read it, not a procedural step in the digital forensic process. While examiners frequently encounter encrypted devices and may need to bypass or decrypt them using keys, memory dumps, or brute-force methods, this is a technical challenge encountered during collection or examination, not a separate phase. The standard essential steps remain collection, examination, analysis, and reporting.

  • ✓

    Collection

    Why this is correct

    Collection is the critical first phase in which digital evidence is identified, preserved, and acquired from original sources, including imaging hard drives, capturing volatile memory, and recording metadata with a documented chain of custody. Forensic examiners use write-blockers and compute cryptographic hashes, such as SHA-256, before and after acquisition to prove that the evidence was not altered. This step is essential because every later conclusion depends on the integrity and completeness of the collected evidence.

  • ✗

    Destruction

    Why it's wrong here

    Destruction, such as degaussing, physical shredding, or secure data wiping, is an end-of-life data-sanitization practice, not a standard phase of forensic investigation. The forensic process is founded on preserving evidence, so intentionally destroying data would undermine admissibility and obstruct investigation. Although courts may eventually authorize disposition of evidence after a case concludes, that is a legal or administrative action, not an essential forensic process step.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.