CHFI Computer Forensics Fundamentals and Process Practice Question
In a UK-based investigation, the police seize a computer without a warrant. The suspect's lawyer argues that the evidence is inadmissible because it violates which law?
⚠ Common exam trap
EC-Council often tests the distinction between US constitutional law (Fourth Amendment) and UK statutory law (PACE), causing candidates to mistakenly apply US legal principles to a UK scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Police and Criminal Evidence Act (PACE)
The Police and Criminal Evidence Act (PACE) 1984 governs the powers of police in England and Wales to search, seize, and retain evidence. Without a warrant, the seizure of a computer likely violates PACE's requirements for lawful entry and seizure, making the evidence inadmissible under UK law.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Police and Criminal Evidence Act (PACE)
Why this is correct
The Police and Criminal Evidence Act 1984 (PACE) is the primary statutory framework governing police powers to search premises and seize property in England and Wales. Where a computer is lawfully seized, PACE and its Codes of Practice impose conditions on how the device is handled, including making an inventory, and subsequent forensic examination must respect the scope of the original warrant or power. This makes PACE the correct legal basis for the seizure, not any constitutional, data-protection, or computer-offence statute.
- ✗
Fourth Amendment to the US Constitution
Why it's wrong here
The Fourth Amendment protects U.S. persons against unreasonable searches and seizures by federal/state governments; it is a constitutional limitation on U.S. law enforcement, not a grant of power to U.K. police. Since the investigation is UK-based, the Fourth Amendment has no jurisdiction or application, and any challenge to the seizure would be assessed under PACE and the Human Rights Act (Article 8 ECHR), not U.S. jurisprudence.
- ✗
General Data Protection Regulation (GDPR)
Why it's wrong here
The GDPR governs the processing of personal data and grants data subject rights, but it does not contain search-and-seizure powers for law enforcement. While a seized computer will contain personal data, the lawfulness of the seizure itself is determined by PACE, and subsequent police processing is governed by the Law Enforcement Directive implemented in the UK as Part 3 of the Data Protection Act 2018. GDPR is therefore not the legal basis for the seizure.
- ✗
Computer Misuse Act
Why it's wrong here
The Computer Misuse Act 1990 creates offenses such as unauthorized access and unauthorized acts with intent to impair operation of a computer, and it does not confer any power of search or seizure on the police. When police seize a computer under a warrant, they are acting with legal authority, so their conduct is not 'unauthorized access' under the Act. The CMA is substantively different from PACE because it is a criminal statute penalizing computer misuse, not a procedural code governing evidence seizure.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.