
EC-CouncilComputer Hacking Forensic Investigator
Domain 2Objective 2
Data Acquisition and Duplication CHFI Practice Questions (Page 8)
Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.
56questions here
12free pages
14concepts
Questions 36–40
- 36
What is the purpose of hashing an acquired forensic image?
Select an answer first - 37
A forensic examiner is acquiring evidence from a corporate laptop. The laptop is owned by the company, and the employee is suspected of data theft. The examiner must ensure that the evidence is admissible in court and that the company's legal team is satisfied. Which action is most important to maintain the chain of custody?
Select an answer first - 38
What is a key feature of the Linux 'dd' command used in forensic acquisition?
Select an answer first - 39
Which of the following is a key element of a proper chain of custody record?
Select an answer first - 40
What is a primary challenge of remote acquisition?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.