Courseiva
Computer Forensics Fundamentals and ProcessmediumMultiple ChoiceObjective-mapped

CHFI Computer Forensics Fundamentals and Process Practice Question

During a forensic examination of a Windows system, the investigator finds a file named 'notes.txt' that contains a list of passwords. The file's last modified timestamp is before the incident date, but its last accessed timestamp is during the incident. Which type of evidence is this file considered?

⚠ Common exam trap

EC-Council often tests the distinction between direct and circumstantial evidence by presenting timestamp data that shows access without modification, leading candidates to mistakenly classify it as direct evidence because they assume 'accessed during incident' equals 'used in the incident'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Circumstantial evidence

The file 'notes.txt' has a last modified timestamp before the incident but a last accessed timestamp during the incident. This indicates the file was opened or read during the incident, but not modified. Such indirect evidence suggests the attacker may have viewed the passwords, but does not directly prove the act of using them. Therefore, it is circumstantial evidence because it requires inference to connect the file access to the incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Circumstantial evidence

    Why this is correct

    Circumstantial evidence: The access timestamp is circumstantial because it only supports an inference that the file was opened or read, without directly proving who performed the action or under what circumstances. Other processes—such as antivirus scans, Windows Search indexing, or backup software—can update the Last Access Time without any user actually opening the file. Thus, the timestamp alone requires additional corroboration to establish a fact, making it inherently indirect and therefore circumstantial evidence.

  • Best evidence

    Why it's wrong here

    Best evidence: The best evidence rule is a legal doctrine requiring the original document or recording when the content of that document is at issue, rather than a classification of evidentiary weight based on probative value. This file copy or its metadata could indeed be an original artifact, but the label 'best evidence' refers to the preference for originals over duplicates, not to whether the timestamp is strong or weak proof. It is incorrect here because the question is about the inferential nature of the evidence, not about document authenticity or the rule against secondary evidence.

  • Hearsay evidence

    Why it's wrong here

    Hearsay evidence: Hearsay is an out-of-court statement made by a person, offered for the truth of the matter asserted; a file's access timestamp is not a human assertion but rather a machine-generated system attribute. Since there is no declarant, no assertion, and no intent to communicate, the timestamp cannot be hearsay. Digital forensic artifacts like timestamps are considered real or circumstantial evidence of system events, not testimonial statements subject to the hearsay rule.

  • Direct evidence

    Why it's wrong here

    Direct evidence: Direct evidence would prove the fact of who accessed the file without any intervening inference, such as eyewitness testimony or a surveillance video showing the suspect physically opening the file. The access timestamp merely establishes that some access event occurred at a particular time; it does not directly identify the user, the process, or the method of access. Therefore, calling it direct evidence is incorrect because it requires inference to connect the timestamp to the accused's actions.

About these practice questions

One of 205 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.