ExamRange
Home ExamRange Practice Tests
This simulation focuses on live device handling and evidence preservation in digital forensics. You will learn the critical first steps of securing a mobile device to prevent data spoliation and maintain the chain of custody.

CHFI (312-49) Digital Forensics Simulation

Investigation Scenario

A specialized digital forensics task force executes a warrant at a known safe house connected to a human-trafficking syndicate in Denver, Colorado. Upon entry, investigators secure the primary suspect. On the kitchen counter, an investigator locates the suspect's smartphone. The device's screen is currently illuminated, and it is actively displaying an unlocked state with a secure messaging application open. Intelligence suggests the syndicate employs remote-wiping protocols (via Mobile Device Management or Find My services) immediately upon suspect apprehension.

Evidence Collected

Question

In a digital-forensics lab in Denver, Colorado, an investigator receives a smartphone seized from a suspect in a human-trafficking case. The device is powered on and unlocked. To prevent remote wiping or unauthorized alterations by the suspect while maintaining the device's current state, what should be the investigator's first step?

Forensic Hint: Consider the device's current lock state. Modern smartphones implement aggressive encryption. If the device loses power, it enters a state where data is much harder to access. What stops remote commands without dropping power?

Expert Analysis

1. What evidence shows

The device is live (Powered ON) and in an After First Unlock (AFU) state. Active network indicators show an established connection to cellular and wireless networks, presenting an immediate threat of remote data spoliation.

2. Identify forensic stage

Preservation & Scene Securing (First Responder Phase).

3. Why correct answer is correct

Isolating the device from wireless networks (Option A) is the mandatory first step. A Faraday bag or box blocks all Radio Frequency (RF) signals, neutralizing the threat of a remote wipe command reaching the device. Doing this while keeping the device powered on preserves the highly valuable unlocked (AFU) state, allowing for logical or file-system level extractions later in the lab.

4. Why others are wrong

B: Physical acquisition cannot be performed "immediately" in the field without proper network isolation first; connecting cables takes time during which a wipe could execute.
C: Shutting down a modern encrypted smartphone forces it into a Before First Unlock (BFU) state. In BFU, the encryption keys are flushed from RAM, making user data completely inaccessible without the PIN/Passcode.
D: Hardware write-blockers are primarily used for hard drives (SATA/IDE/NVMe). Connecting a live mobile device to a workstation does not isolate it from cellular networks and risks initiating automated syncing or OS updates.

5. Real-world forensic action

The investigator places the device in a validated Faraday bag immediately. If the device is unlocked, settings should be quickly adjusted to disable auto-lock (screen timeout) before isolation, and it should be connected to a portable power bank inside the Faraday enclosure to ensure it does not lose power during transport to the forensic lab.

6. Mini Lesson: Mobile Device States & Preservation

Mobile forensics hinges on two states: BFU (Before First Unlock) and AFU (After First Unlock). In AFU, encryption keys reside in the device's memory, making data extraction significantly easier. In BFU (after a reboot or shutdown), keys are purged. Therefore, the cardinal rule of modern mobile forensics is: If it's on, leave it on; isolate it from networks; supply it with power.

Ready to master digital forensics?

Explore more CHFI simulations