Forensic Investigation Process Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Forensic Investigation Process flashcards as text
During a forensic investigation, which principle ensures that evidence collected is admissible in a court of law?
Answer: Chain of custody
Chain of custody documents every person who handled the evidence, ensuring its integrity and admissibility in court.
A forensic investigator discovers volatile data on a running system. According to the order of volatility, what should be collected FIRST?
Answer: CPU registers and cache
CPU registers and cache are the most volatile data and must be collected first as they are lost immediately upon power-off.
Which document formally authorizes a forensic investigator to conduct an investigation within an organization?
Answer: Written authorization or letter of engagement
A written authorization or letter of engagement from the organization legally authorizes the investigator to examine its systems.
What is the primary purpose of a forensic investigation report?
Answer: To document findings in a legally defensible and comprehensible manner
The forensic report must document findings clearly and in a legally defensible way so it can be used in judicial or corporate proceedings.
In the CHFI investigation methodology, what is the correct sequence of the initial phases?
Answer: Identification, Preservation, Collection, Examination
The standard forensic process begins with Identification, then Preservation, then Collection, followed by Examination and Analysis.
A forensic examiner uses write-blockers when imaging a hard drive. What is the main reason for using a write-blocker?
Answer: To prevent any modification to the original evidence drive
Write-blockers prevent any write operations from reaching the original drive, maintaining its forensic integrity.
Which hashing algorithm is most commonly used in CHFI to verify the integrity of forensic disk images?
Answer: MD5 or SHA-1
MD5 and SHA-1 (and increasingly SHA-256) are used to generate hash values that verify a forensic image is an exact copy of the original.