Courseiva

Direct vs Circumstantial Evidence in Digital Forensics

Which type of evidence is a witness's statement that they saw someone log into a computer?

⚠ Common exam trap

EC-Council often tests the distinction between direct and circumstantial evidence by presenting a scenario where a witness sees a result (e.g., a screen displaying a file) and candidates mistakenly classify it as direct evidence of the action (e.g., file access) when it is actually circumstantial evidence requiring an inference.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Direct evidence

Direct evidence is testimony or other proof that directly proves a fact without requiring any inference. A witness's statement that they saw someone log into a computer is direct evidence because it is based on the witness's firsthand observation of the act itself, not on any deduction or assumption. In digital forensics, direct evidence can include eyewitness accounts of specific actions on a system, such as entering credentials or accessing files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hearsay evidence

    Why it's wrong here

    Hearsay is an out-of-court statement offered to prove its truth; the witness here testifies from direct personal observation, so it is direct evidence. It is tempting because testimony repeating what another person said—such as a colleague describing the login—would indeed be hearsay and inadmissible in most proceedings.

  • ✗

    Best evidence

    Why it's wrong here

    Best evidence requires the original document or object itself, not oral testimony, so a witness account of a login cannot qualify. It is tempting because witness statements feel authoritative, but best evidence applies to proving a document's contents in court, where the original writing itself must be produced.

  • ✗

    Circumstantial evidence

    Why it's wrong here

    Circumstantial evidence requires inference to connect it to the fact; a witness's direct observation of the login proves the act without inference, making it direct evidence. It is tempting because circumstantial evidence is common in computer crime cases, such as login logs implying who was at the keyboard.

  • ✓

    Direct evidence

    Why this is correct

    Direct evidence proves a fact without inference. A witness testifying that they personally saw someone log into a computer directly establishes that act, unlike circumstantial evidence, which would require reasoning from other facts to reach the same conclusion.

Go deeper

Related to this question

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a forensic examination of a Windows system, the investigator finds a file named 'notes.txt' that contains a list of passwords. The file's last modified timestamp is before the incident date, but its last accessed timestamp is during the incident. Which type of evidence is this file considered?

medium
  • ✓ A.Circumstantial evidence
  • B.Best evidence
  • C.Hearsay evidence
  • D.Direct evidence

Why A: The file 'notes.txt' has a last modified timestamp before the incident but a last accessed timestamp during the incident. This indicates the file was opened or read during the incident, but not modified. Such indirect evidence suggests the attacker may have viewed the passwords, but does not directly prove the act of using them. Therefore, it is circumstantial evidence because it requires inference to connect the file access to the incident.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.