Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

Which TWO of the following are types of write blockers used in forensic imaging? (Select two.)

⚠ Common exam trap

EC-Council often tests the distinction between integrity verification (hashing) and write prevention, leading candidates to mistakenly select 'Hash write blocker' as a valid type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hardware write blocker

Hardware write blockers (D) are physical devices that sit between the suspect drive and the forensic workstation, intercepting the ATA/SCSI/NVMe command set and permitting only read commands to pass through, which prevents any modification of the evidence drive. Software write blockers (E) are drivers or kernel modules (for example, on Linux, mounting with the read-only option or using tools like the 'blockdev --setro' command) that intercept I/O requests at the OS level and block write operations to the protected device. These two are the recognized categories of write blockers in forensic imaging because they operate at the hardware and software layers respectively. Encryption write blockers (A) are not a write-blocking type — encryption is a data protection mechanism, not a means of preventing writes during acquisition. Network write blockers (B) do not exist as a forensic write-blocker category, since network interfaces are not the medium being protected during imaging. Hash write blockers (C) are also not a real category; hashing (e.g., MD5/SHA-256) is used to verify integrity after imaging, not to block writes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encryption write blocker

    Why it's wrong here

    Encryption is a data confidentiality technique that obscures content via algorithms such as AES, but it does not affect the underlying I/O command path. A forensic write blocker must physically or logically suppress write commands to preserve evidence, whereas encryption merely transforms data and still permits writes to occur. Thus, an encryption write blocker is a misnomer because encryption cannot prevent alteration of the storage medium.

  • ✗

    Network write blocker

    Why it's wrong here

    A network write blocker is not a recognized forensic tool because write blocking operates at the bus or driver layer, not at the network protocol level. Network traffic can be filtered or redirected, but those actions do not intercept disk-level write commands from the operating system to the evidence drive. Therefore, networking concepts are irrelevant to preventing writes during forensic acquisition.

  • ✗

    Hash write blocker

    Why it's wrong here

    Hashing, such as SHA-256 or MD5, is used to generate a digital fingerprint for integrity verification, not to control write access. A hash algorithm passively computes a value from data and has no mechanism to inspect or block incoming write commands in the I/O path. Confusing hashing with write blocking conflates evidence validation with evidence preservation, which are separate forensic functions.

  • ✓

    Hardware write blocker

    Why this is correct

    Hardware write blockers are physical devices installed inline between the suspect drive and the forensic workstation, such as a Tableau bridge or a forensic SATA dock. They operate at the ATA, SATA, or USB command level to allow only read commands to pass while blocking write commands at the hardware interface. This provides an OS-independent, tamper-resistant method for preserving the original evidence bit-for-bit during imaging.

  • ✓

    Software write blocker

    Why this is correct

    Software write blockers are programs or kernel-level filter drivers that intercept I/O requests from the operating system to the evidence drive, discarding any write operation. They run on the forensic workstation and must be carefully configured to affect only the target drive, leaving other drives writable. Unlike hardware blockers, they rely on the host OS and can be vulnerable to bypass if the kernel is compromised, but they still serve the same preservation purpose.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.