Certified Incident Handler (CIH) Practice Ecam

Disable ads (and more) with a membership for a one time $2.99 payment

Prepare for the Certified Incident Handler (CIH) Exam. Enhance your knowledge with interactive quizzes and detailed insights into cyber incident handling. Boost your exam readiness with our expert-designed questions!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


What is the first step to shutting down a Windows OS system after evidence collection?

  1. Click the Windows button

  2. Document any running programs

  3. Take a photograph of the screen

  4. Click the Power option from the menu

The correct answer is: Click the Power option from the menu

When shutting down a Windows OS system after evidence collection, the primary objective is to ensure that potential volatile data is preserved while preventing the alteration of any evidence. The best practice for accomplishing this is to utilize the built-in power options, which provide a systematic way to properly shut down the system without risking corruption of data or loss of volatile information. By accessing the Power option from the menu, you initiate a controlled shutdown that adheres to the operating system’s protocols for closing applications and processes safely. This process helps maintain the integrity of any stored evidence, as it allows Windows to finish writing any pending data to disk and closing applications orderly, which is crucial for the forensics involved. Other options, while potentially useful in specific scenarios, do not prioritize the methodology needed for a proper shutdown in the context of evidence integrity. For instance, documenting running programs and taking screenshots can be important steps in evidence collection, but they do not directly contribute to safely shutting down the system. Clicking the Windows button, although it might provide access to shutdown options, lacks the specificity and safety of selecting the Power option directly. This structured approach ensures the shutdown process is managed correctly while preserving the continuity and reliability of the evidence collected.