CHFI Computer Forensics Lab Practice Question
Which TWO of the following are essential components of a computer forensics lab according to CHFI best practices?
⚠ Common exam trap
EC-Council often tests the distinction between 'nice-to-have' items (like coffee machines) and mandatory security components (like controlled-access evidence storage), leading candidates to select convenience over critical infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evidence storage area with controlled access
Option B is correct because CHFI best practices require a physically secure evidence storage area with controlled access to preserve the chain of custody and prevent tampering, theft, or contamination of digital evidence. Option E is correct because a forensic workstation loaded with specialized tools (e.g., EnCase, FTK, write blockers, and hashing utilities) is the core hardware/software platform needed to acquire, image, and analyze evidence without altering it. The other options are not essential lab components: a server farm (A) is unnecessary for typical forensic analysis, a public-facing website (C) would actually create security and confidentiality risks, and a coffee machine (D) is merely a convenience item with no forensic function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server farm for data processing
Why it's wrong here
A server farm for data processing is not an essential component of a digital forensics laboratory because heavy processing tasks, such as hash generation or image indexing, can be outsourced to cloud services or performed on the forensic workstations themselves. The core laboratory requirements center on evidence integrity, chain of custody, and proper analysis tools, none of which mandate a centralized server infrastructure. While a lab may choose to add servers for convenience, their absence does not impair legally sound forensic analysis.
- ✓
Evidence storage area with controlled access
Why this is correct
Evidence storage area with controlled access is essential to a forensic lab because it establishes a physically secure, restricted environment where seized media can be preserved, inventoried, and protected from tampering, environmental damage, or unauthorized access. This directly supports the chain of custody and evidentiary integrity that courts require for admissibility, and is a core component per forensic laboratory best-practice standards. Without such an area, the entire examination process loses its evidentiary foundation.
- ✗
Public-facing website for case management
Why it's wrong here
A public-facing website for case management is not an essential lab component; forensic case management must remain confidential and internally accessible, not exposed to the internet where it risks leaking case data or violating privacy rules. Secure internal case tracking software is useful, but a public-facing portal is actually a security liability and is unrelated to the physical and procedural elements required for evidence analysis. Therefore its presence is optional and, in many contexts, undesirable.
- ✗
Coffee machine for staff convenience
Why it's wrong here
A coffee machine for staff convenience is not essential because staff amenities do not affect the scientific validity or forensic soundness of the evidence examination process. Although refreshment may improve examiner morale, it plays no role in evidence preservation, analysis, or reporting, and is therefore not a component that a laboratory audit or accreditation standard would require.
- ✓
Forensic workstation with specialized software
Why this is correct
A forensic workstation with specialized software is required for the actual examination and analysis of digital evidence, providing the necessary platform for disk imaging, carving, keyword searches, and artifact extraction using validated tools. In addition to software, the workstation must incorporate write-blockers and follow procedures to ensure data is not altered, making it a core functional element whose capabilities directly determine what evidence can be recovered. This is why it is considered an essential component of a computer forensics lab.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.