Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

Which TWO of the following are essential steps that a first responder should take when arriving at a digital crime scene? (Select TWO)

⚠ Common exam trap

EC-Council often tests the misconception that imaging the hard drive is the first priority, but the trap here is that volatile data (RAM, network state) must be captured first to prevent permanent loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture volatile data from running systems

Option A is correct because volatile data such as RAM contents, running processes, network connections, and open files will be lost on shutdown or reboot, so a first responder must capture it using tools like memory dumps or live-response utilities before powering down the system. Option E is correct because photographing and documenting the scene preserves the original state and chain of custody, recording the physical layout, cable connections, and system status before any evidence is altered. Option B is not an essential first-responder step because forensic imaging is typically performed later by a forensic examiner after volatile data is secured and the scene is documented, and imaging a running system prematurely can destroy volatile evidence. Option C is wrong because installing software on the suspect's computer modifies the system and contaminates evidence, violating the principle of least intrusion. Option D is wrong because witness interviews must be documented to maintain an accurate and admissible record; undocumented interviews are unreliable and not an essential first-responder action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Capture volatile data from running systems

    Why this is correct

    Volatile data resides only in memory and other transient system states that vanish when the system loses power; capturing it first is imperative. As a first responder, collect RAM contents, active network connections, and running processes before powering down, using trusted forensic utilities from external media. This preserves ephemeral evidence such as encryption keys, attacker command lines, and in-memory malware that would otherwise be permanently lost.

  • ✗

    Immediately start the forensic imaging process

    Why it's wrong here

    Immediate forensic imaging is premature because the scene and system must first be secured and documented; booting into an imaging environment alters the evidence before a baseline record exists. A proper responding officer verifies identity, secures the area, records hardware configuration, and only then performs imaging with a write-blocker to maintain evidentiary integrity. Jumping straight to imaging risks invalidating the case due to undocumented changes and lost context.

  • ✗

    Install forensic software on the suspect's computer

    Why it's wrong here

    Installing forensic software directly onto the suspect's computer is a serious error because the installation process itself writes files, modifies filesystem metadata, and can overwrite the exact artifacts needed to prove the case. This contamination violates the forensic principle that the original evidence must not be modified by the acquisition process. Any tool should be executed from a trusted, write-protected forensic boot medium, never installed onto the target system.

  • ✗

    Interview all witnesses without documentation

    Why it's wrong here

    Conducting witness interviews without contemporaneous documentation destroys the probative value of statements because memory fades and defense counsel can successfully challenge unrecorded recollections. A first responder should take written notes, record the interview, or obtain a signed statement; otherwise the information is unreliable. In addition, interviews must not displace the immediate stabilization of the scene and capture of volatile data.

  • ✓

    Photograph and document the scene

    Why this is correct

    Photographing and documenting the entire scene is an essential step because it captures the original condition of hardware, connections, cable placements, and physical context before anything is moved or powered off. This visual record supports the chain of custody and shows that evidence was not tampered with or planted. Detailed labels, diagrams, and a written summary later let examiners reconstruct exactly how the system was found.

Go deeper

Related to this question

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.