Courseiva
Computer Forensics Lab →mediumMultiple Choice

CHFI Computer Forensics Lab Practice Question

A forensic lab is establishing a chain of custody procedure. Which practice is considered best according to CHFI guidelines?

⚠ Common exam trap

EC-Council often tests the distinction between security controls (like encryption or access restrictions) and procedural documentation (like signatures and timestamps), leading candidates to confuse physical or technical safeguards with the legal requirement for an auditable chain of custody.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document every transfer of evidence with signatures and timestamps

The chain of custody is fundamentally a legal and procedural requirement to demonstrate the integrity and admissibility of digital evidence. CHFI guidelines emphasize that every transfer of evidence must be meticulously documented with signatures, timestamps, and purpose to create an unbroken audit trail, which is the only practice that directly satisfies the legal standard for evidence handling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require biometric authentication for all lab personnel

    Why it's wrong here

    Biometric authentication verifies the identity of personnel attempting to access lab systems or evidence storage, but it does not track the movement of specific evidence items. A chain of custody requires a documented chronological history of each transfer, including who released and who received the evidence, with timestamps. Biometric access logs may show who entered a room, but they do not establish custody over a particular digital exhibit or forensic image. Therefore, while useful for access control, it is not a substitute for custody documentation.

  • ✗

    Store evidence in a secure room with limited access

    Why it's wrong here

    Restricting physical access to a secure evidence room reduces the risk of unauthorized tampering, yet it fails to document the individual who handled a specific piece of evidence at any given moment. Chain-of-custody protocols mandate a written or electronic log recording each removal, transfer, and return of evidence, along with the identities and signatures of the custodians. A limited-access policy alone cannot prove that the evidence has not been altered between collection and presentation in court. Physical security is a complementary control, not a custody record.

  • ✗

    Use encryption to protect evidence files

    Why it's wrong here

    Encryption protects the confidentiality and integrity of digital evidence while at rest or in transit, but it does not generate an auditable record of human custody. The chain of custody traces possession and control of the physical or logical evidence object, requiring signatures and timestamps for every change of hands. An encrypted container might preserve the evidence's content, but it cannot show who accessed the decrypted copy or when a forensic image was transferred. Thus, crypto safeguards data, while custody documentation safeguards legal admissibility.

  • ✓

    Document every transfer of evidence with signatures and timestamps

    Why this is correct

    Proper chain-of-custody documentation requires an unbroken chronological record that identifies every individual who had control of the evidence, the exact date and time of each transfer, and the reason for the transfer. Each exchange must be signed by both the releasing and receiving custodians to verify that the evidence was in their possession and was not unaccounted for. This documentation is pivotal in court to demonstrate that the evidence is authentic and has not been substituted, altered, or tampered with. Without signatures and timestamps, a court may deem the evidence inadmissible on the grounds of a broken custody chain.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.