
EC-CouncilComputer Hacking Forensic Investigator
Domain 2Objective 2
Data Acquisition and Duplication CHFI Practice Questions (Page 7)
Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.
56questions here
12free pages
14concepts
Questions 31–35
- 31
A forensic examiner acquires a hard drive from a crime scene and later testifies in court. The defense attorney challenges the admissibility of the evidence, claiming the drive could have been tampered with after seizure. Which documentation or process would best refute this claim?
Select an answer first - 32
A system administrator copies a suspect's hard drive to another drive using the Windows 'copy' command, then hands it to a forensic examiner. The examiner refuses to analyze the copy. Why is the copy not acceptable as forensic evidence?
Select an answer first - 33
In which situation would a sparse acquisition be most beneficial?
Select an answer first - 34
An examiner is investigating a case involving a 2 TB drive. The investigation only requires specific files from a particular folder, but the examiner is concerned about deleted files that may be relevant. The examiner has limited time and storage. Which acquisition strategy best balances the need for deleted files, time, and storage?
Select an answer first - 35
An examiner is asked to provide a copy of a suspect's hard drive to the defense team. The examiner creates a bit-stream image of the drive and provides the image file. The defense team claims that the image is not a true duplicate because it is a single file. Which response is most accurate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.