CHFI Computer Forensics Fundamentals and Process Practice Question
According to Locard's exchange principle, which of the following is MOST relevant to digital forensics?
⚠ Common exam trap
The CHFI exam often tests the misconception that Locard's exchange principle applies only to physical evidence (like fingerprints or DNA), leading candidates to incorrectly choose option C, when in fact the principle is equally valid for digital traces such as log entries, file metadata, and memory artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
When a person interacts with a digital device, they leave digital traces that can be recovered
Locard's exchange principle states that every contact leaves a trace. In digital forensics, this translates to the fact that when a person interacts with a digital device (e.g., opening a file, browsing a website, or typing a command), they leave digital traces such as log entries, metadata, temporary files, or registry artifacts. These traces can be recovered and analyzed to reconstruct user activity, making option B the most relevant application of the principle in this context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The chain of custody must be maintained for all evidence
Why it's wrong here
Chain of custody is a legal and procedural requirement that governs how evidence is documented, preserved, and passed from one handler to the next to maintain admissibility in court. It is not a scientific principle describing trace transfer, but rather an administrative safeguard. Locard's exchange principle concerns the physical or digital transfer of trace material, which is an empirical phenomenon, not a documentation rule. Thus, while essential, chain of custody is not the digital adaptation of Locard's principle.
- ✓
When a person interacts with a digital device, they leave digital traces that can be recovered
Why this is correct
This is the direct digital adaptation of Locard's exchange principle: every interaction with a digital device leaves residual traces, such as file metadata changes, prefetch cache entries, registry modification times, network connection logs, or remnants in RAM. Those traces may be volatile or persistent, but their existence is the foundational premise of digital forensics. Because user actions necessarily alter the device's state, examiners can reconstruct activity by identifying and analyzing these digital footprints. Therefore, this statement accurately reflects how Locard's principle applies to digital investigations.
- ✗
Every crime scene contains at least one latent fingerprint
Why it's wrong here
The claim that every crime scene contains at least one latent fingerprint is both false and far too narrow to represent Locard's principle. Locard's exchange is a general scientific law stating that any contact leaves a trace, but that trace may be biologic, chemical, physical, or digital, and it may be absent if the perpetrator wore gloves, cleaned the area, or used tools. A latent fingerprint is merely one specific example of a transferable trace, not a universal requirement. Consequently, this option mistakes a particular type of evidence for the general principle itself.
- ✗
Digital evidence is always stored in non-volatile memory
Why it's wrong here
Digital evidence is not always stored in non-volatile memory; it can reside in volatile RAM, processor caches, network buffers, or other ephemeral storage that is lost upon power loss or reboot. The assertion that it is always stored in non-volatile memory is factually incorrect and also irrelevant to Locard's principle. Volatile digital traces are often critical to an investigation and require special collection techniques like memory dumps. Locard's principle addresses the production of traces, not the medium where they persist, so this option mischaracterizes both the principle and digital evidence characteristics.
Go deeper
Related to this question
Learn chapter
Windows Forensics: File Systems and Artifacts
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.