
EC-CouncilComputer Hacking Forensic Investigator
Domain 2Objective 2
Data Acquisition and Duplication CHFI Practice Questions (Page 11)
Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.
56questions here
12free pages
14concepts
Questions 51–55
- 51
What is the primary purpose of a hardware write blocker?
Select an answer first - 52
An examiner is imaging a suspect's laptop drive using a hardware write blocker. The imaging tool reports that the drive is write-protected, but the examiner notices that the drive's SMART attributes show an increase in the 'Power-On Hours' during the acquisition. What is the most likely explanation?
Select an answer first - 53
A forensic examiner is about to image a suspect's SATA hard drive. The examiner connects the drive to a forensic workstation using a hardware write blocker. What is the primary purpose of using the write blocker in this scenario?
Select an answer first - 54
An examiner needs to acquire data from a RAID 5 array that is part of a server involved in an investigation. The server is running and the RAID controller is functional. Which acquisition approach is most appropriate?
Select an answer first - 55
A forensic examiner is called to investigate a suspected data breach. The affected server is running a critical application that cannot be stopped. The examiner must collect evidence that will be admissible in court. The server is located in a remote data center, and the examiner is at the corporate office. Which combination of actions best balances the need for volatile data, system availability, and legal admissibility?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.