Courseiva
Computer Forensics Fundamentals and ProcessmediumMultiple ChoiceObjective-mapped

CHFI Computer Forensics Fundamentals and Process Practice Question

During a forensic investigation, a lawyer objects to the admissibility of a log file on the grounds that it is hearsay. Which of the following is the BEST argument to overcome this objection?

⚠ Common exam trap

EC-Council often tests the misconception that 'best evidence' or 'original record' automatically overcomes hearsay, but the trap here is that hearsay and best evidence are separate evidentiary rules, and only a specific exception like business records can defeat a hearsay objection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The log file qualifies as a business record exception to the hearsay rule.

The log file is admissible under the business records exception to the hearsay rule (Federal Rule of Evidence 803(6)). This exception applies because logs are created automatically or by a person with knowledge, near the time of the event, in the regular course of business, and it is the regular practice to make such records. In digital forensics, system logs (e.g., Windows Event Logs, syslog) are routinely admitted under this exception, as they are generated by the system without the declarant's bias or memory issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The log file qualifies as a business record exception to the hearsay rule.

    Why this is correct

    Under FRE 803(6), a log file is admissible as a business record if it was created at or near the time of the event by a person with knowledge, kept in the regular course of business, and it was the regular practice to make such a record. The custodian or qualified witness must lay a foundation, but once established, the log is an exception to the hearsay rule, not excluded as hearsay. This exception reflects the reliability of records routinely relied upon in business operations.

  • The log file is circumstantial evidence, not hearsay.

    Why it's wrong here

    Calling the log 'circumstantial evidence' confuses the direct/circumstantial distinction with the hearsay rule. Circumstantial evidence is evidence from which a fact is inferred, but hearsay is an out-of-court statement offered for the truth of the matter asserted. An automated log entry is an assertion (e.g., 'IP X connected at 10:00'), so if offered to prove that connection occurred, it is hearsay regardless of whether it also happens to be circumstantial evidence of a broader intrusion.

  • The log file is direct evidence of the intrusion.

    Why it's wrong here

    The log does not directly prove the intrusion itself; it only shows records of activities such as login attempts or connections, from which an intrusion may be inferred. Direct evidence would be testimony from an eyewitness that they saw the attacker, or an admission from the attacker—neither of which a log provides. Moreover, being 'direct' does not bypass the hearsay problem: the log is still an out-of-court statement offered for its truth, so it must satisfy a hearsay exception.

  • The log file is the best evidence because it is an original record.

    Why it's wrong here

    The best evidence rule, which requires the original writing when proving the content of a writing, is an authentication and completeness doctrine; it is separate from the hearsay rule. Even if the log file is an original record, that designation does not address the hearsay objection because the log's content is an out-of-court assertion offered for its truth. The original log can still be excluded as hearsay unless it falls under an exception like the business records rule.

Go deeper

Related to this question

About these practice questions

This CHFI question is part of Courseiva's 205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.