Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

Which two of the following are tools used for memory forensics acquisition? (Choose TWO.)

⚠ Common exam trap

EC-Council often tests the distinction between memory acquisition tools (which capture RAM) and memory analysis tools (which examine captured dumps), so candidates may mistakenly choose Volatility (a popular analysis tool) as an acquisition tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WinPmem

WinPmem (C) is a memory acquisition tool that captures physical memory from live Windows systems into a raw image file, making it a correct choice for memory forensics acquisition. LiME (E) is a Loadable Kernel Module for Linux that acquires volatile memory to a file or over the network, and it is specifically designed for memory acquisition, so it is also correct. Autopsy (A) is a graphical digital forensics platform used primarily for disk image analysis and file system examination, not memory acquisition. FTK Imager (B) is used for creating forensic disk images and mounting images, not for capturing RAM. Volatility (D) is a memory analysis framework that parses memory images after acquisition, so it is not an acquisition tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Autopsy

    Why it's wrong here

    Autopsy is a Java-based digital forensics platform designed primarily for disk image analysis, offering modules for file carving, keyword extraction, and timeline reconstruction from acquired storage media. It does not provide a mechanism for capturing or directly parsing raw physical memory dumps, as its architecture is built around filesystem and deleted-file recovery rather than volatile memory structures. Therefore, it is not a memory acquisition tool.

  • ✗

    FTK Imager

    Why it's wrong here

    FTK Imager is a forensic imaging utility focused on creating exact, bit-for-bit duplicates of hard drives and other non-volatile storage, and it also allows previewing of evidence drives. While some builds include a 'Capture Memory' menu option for saving a RAM dump, the tool's core purpose is disk imaging and its memory-capture feature is non-standard, lacking the kernel-level reliability and chain-of-custody controls of dedicated memory acquisition software. Hence, it is not the intended tool for memory forensics.

  • ✓

    WinPmem

    Why this is correct

    WinPmem is a dedicated memory acquisition tool for Windows that loads a kernel-mode driver to map and copy physical memory (RAM) into a raw image or an AFF4 container. Developed by the Rekall project and now maintained as part of the pmem suite, it is specifically engineered to produce a faithful snapshot of volatile memory for later analysis with Volatility or Rekall. Therefore, it is correct as a memory forensic acquisition utility.

  • ✗

    Volatility

    Why it's wrong here

    Volatility is a robust open-source analysis framework for dissecting memory images, capable of enumerating processes, network sockets, loaded kernel modules, and injected code from a RAM dump. It does not itself acquire or capture memory; rather, it reads pre-existing memory images produced by tools like WinPmem or LiME, making it an analysis platform, not an acquisition tool. This classification places it outside the scope of memory acquisition tools.

  • ✓

    LiME

    Why this is correct

    LiME (Linux Memory Extractor) is a Loadable Kernel Module that enables direct, forensically sound acquisition of volatile memory from Linux and Android systems by reading physical memory and streaming it out to a user-specified destination. Because it runs within the kernel, it can capture a coherent snapshot of RAM even on systems where /dev/mem access is restricted, making it the standard for Linux memory acquisition. Thus, it is correct.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.