CHFI Computer Forensics Lab Practice Question
You are a forensic examiner at a corporate security firm. You receive a laptop from the HR department that belonged to a terminated employee. The laptop was used for company business and is suspected of containing unauthorized file-sharing software. The laptop is running Windows 10 with BitLocker drive encryption enabled. Before shutdown, the employee was logged into the system. HR claims the laptop was shut down properly and then handed over within an hour. You are asked to acquire a forensic image of the hard drive for analysis. However, when you boot the laptop, you are prompted for the BitLocker recovery key. HR does not have the key, and the employee refuses to cooperate. The laptop also has a TPM chip. Which of the following is the most appropriate course of action to acquire the data?
⚠ Common exam trap
EC-Council often tests the misconception that a properly shut-down system with TPM will always unlock automatically via TPM. However, the question explicitly states that booting prompts for a recovery key, indicating TPM unlock failed. The trap is to assume D is still correct, but the correct first step is to retrieve the recovery key from Active Directory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contact IT to obtain the BitLocker recovery key from Active Directory.
The laptop was shut down properly, but the boot-time recovery key prompt indicates that the TPM did not automatically release the BitLocker key. In an enterprise environment, the most appropriate first action is to obtain the BitLocker recovery key from Active Directory, where BitLocker recovery information is commonly escrowed. Cold boot attacks and Linux live USB bypass tools are not reliable or authorized first steps, and booting normally again would not resolve the failed TPM unlock and could alter evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Contact IT to obtain the BitLocker recovery key from Active Directory.
Why this is correct
This is the correct first step because corporate BitLocker recovery keys are often backed up to Active Directory. Retrieving it is the most straightforward method to access the drive.
- ✗
Perform a cold boot attack to extract the BitLocker key from memory.
Why it's wrong here
Incorrect: This is a complex and invasive technique that should only be used if normal boot fails.
- ✗
Boot from a Linux live USB and use tools to bypass BitLocker.
Why it's wrong here
Incorrect: Without the key, Linux cannot decrypt the drive.
- ✗
Boot the laptop normally and let BitLocker unlock the drive using the TPM.
Why it's wrong here
This is incorrect because the system is already prompting for a recovery key, meaning the TPM-based unlock did not work. Booting normally will re-prompt for the recovery key, not automatically unlock.
Visual reference
Go deeper
Related to this question
Learn chapter
Linux and Mac Forensics
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.