CHFI Storage Forensics and File System Analysis Practice Question
Which two of the following are tools used for memory forensics acquisition? (Choose TWO.)
⚠ Common exam trap
EC-Council often tests the distinction between memory acquisition tools (which capture RAM) and memory analysis tools (which examine captured dumps), so candidates may mistakenly choose Volatility (a popular analysis tool) as an acquisition tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WinPmem
WinPmem (C) is a memory acquisition tool that captures physical memory from live Windows systems into a raw image file, making it a correct choice for memory forensics acquisition. LiME (E) is a Loadable Kernel Module for Linux that acquires volatile memory to a file or over the network, and it is specifically designed for memory acquisition, so it is also correct. Autopsy (A) is a graphical digital forensics platform used primarily for disk image analysis and file system examination, not memory acquisition. FTK Imager (B) is used for creating forensic disk images and mounting images, not for capturing RAM. Volatility (D) is a memory analysis framework that parses memory images after acquisition, so it is not an acquisition tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Autopsy
Why it's wrong here
Autopsy is a Java-based digital forensics platform designed primarily for disk image analysis, offering modules for file carving, keyword extraction, and timeline reconstruction from acquired storage media. It does not provide a mechanism for capturing or directly parsing raw physical memory dumps, as its architecture is built around filesystem and deleted-file recovery rather than volatile memory structures. Therefore, it is not a memory acquisition tool.
- ✗
FTK Imager
Why it's wrong here
FTK Imager is a forensic imaging utility focused on creating exact, bit-for-bit duplicates of hard drives and other non-volatile storage, and it also allows previewing of evidence drives. While some builds include a 'Capture Memory' menu option for saving a RAM dump, the tool's core purpose is disk imaging and its memory-capture feature is non-standard, lacking the kernel-level reliability and chain-of-custody controls of dedicated memory acquisition software. Hence, it is not the intended tool for memory forensics.
- ✓
WinPmem
Why this is correct
WinPmem is a dedicated memory acquisition tool for Windows that loads a kernel-mode driver to map and copy physical memory (RAM) into a raw image or an AFF4 container. Developed by the Rekall project and now maintained as part of the pmem suite, it is specifically engineered to produce a faithful snapshot of volatile memory for later analysis with Volatility or Rekall. Therefore, it is correct as a memory forensic acquisition utility.
- ✗
Volatility
Why it's wrong here
Volatility is a robust open-source analysis framework for dissecting memory images, capable of enumerating processes, network sockets, loaded kernel modules, and injected code from a RAM dump. It does not itself acquire or capture memory; rather, it reads pre-existing memory images produced by tools like WinPmem or LiME, making it an analysis platform, not an acquisition tool. This classification places it outside the scope of memory acquisition tools.
- ✓
LiME
Why this is correct
LiME (Linux Memory Extractor) is a Loadable Kernel Module that enables direct, forensically sound acquisition of volatile memory from Linux and Android systems by reading physical memory and streaming it out to a user-specified destination. Because it runs within the kernel, it can capture a coherent snapshot of RAM even on systems where /dev/mem access is restricted, making it the standard for Linux memory acquisition. Thus, it is correct.
Go deeper
Related to this question
Learn chapter
Linux and Mac Forensics
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.