Courseiva
Computer Forensics Lab →easyMultiple Choice

CHFI Computer Forensics Lab Practice Question

You are a forensic examiner at a corporate security firm. You receive a laptop from the HR department that belonged to a terminated employee. The laptop was used for company business and is suspected of containing unauthorized file-sharing software. The laptop is running Windows 10 with BitLocker drive encryption enabled. Before shutdown, the employee was logged into the system. HR claims the laptop was shut down properly and then handed over within an hour. You are asked to acquire a forensic image of the hard drive for analysis. However, when you boot the laptop, you are prompted for the BitLocker recovery key. HR does not have the key, and the employee refuses to cooperate. The laptop also has a TPM chip. Which of the following is the most appropriate course of action to acquire the data?

⚠ Common exam trap

EC-Council often tests the misconception that a properly shut-down system with TPM will always unlock automatically via TPM. However, the question explicitly states that booting prompts for a recovery key, indicating TPM unlock failed. The trap is to assume D is still correct, but the correct first step is to retrieve the recovery key from Active Directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Contact IT to obtain the BitLocker recovery key from Active Directory.

The laptop was shut down properly, but the boot-time recovery key prompt indicates that the TPM did not automatically release the BitLocker key. In an enterprise environment, the most appropriate first action is to obtain the BitLocker recovery key from Active Directory, where BitLocker recovery information is commonly escrowed. Cold boot attacks and Linux live USB bypass tools are not reliable or authorized first steps, and booting normally again would not resolve the failed TPM unlock and could alter evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Contact IT to obtain the BitLocker recovery key from Active Directory.

    Why this is correct

    This is the correct first step because corporate BitLocker recovery keys are often backed up to Active Directory. Retrieving it is the most straightforward method to access the drive.

  • ✗

    Perform a cold boot attack to extract the BitLocker key from memory.

    Why it's wrong here

    Incorrect: This is a complex and invasive technique that should only be used if normal boot fails.

  • ✗

    Boot from a Linux live USB and use tools to bypass BitLocker.

    Why it's wrong here

    Incorrect: Without the key, Linux cannot decrypt the drive.

  • ✗

    Boot the laptop normally and let BitLocker unlock the drive using the TPM.

    Why it's wrong here

    This is incorrect because the system is already prompting for a recovery key, meaning the TPM-based unlock did not work. Booting normally will re-prompt for the recovery key, not automatically unlock.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.