CHFI Computer Forensics Fundamentals and Process Practice Question
In the context of e-discovery, what does the 'best evidence rule' require regarding digital documents?
⚠ Common exam trap
EC-Council often tests the misconception that the best evidence rule requires the 'original' in a physical sense, leading candidates to reject reliable duplicates, when in fact digital duplicates verified by hash are legally equivalent to the original under FRE 1003.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
That the original electronic file or a reliable duplicate be produced.
The best evidence rule, codified in Federal Rule of Evidence 1002, requires the original writing, recording, or photograph to prove its content unless otherwise provided. In e-discovery, an original electronic file or a reliable duplicate (e.g., a bit-for-bit forensic image verified by a hash such as MD5 or SHA-1) satisfies this rule because the duplicate is functionally equivalent to the original for evidentiary purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
That the original electronic file or a reliable duplicate be produced.
Why this is correct
Under Fed. R. Evid. 1002, proving a document's content requires the original; for ESI, FRE 1001(d) defines an original as any printout or other readable output that accurately reflects the information. A reliable duplicate—such as a forensic image with a matching SHA-256 hash or a native file produced with verified integrity—is admissible whenever there is no genuine question about the original's authenticity or unfairness from using the copy. In practice, producing the native file or load-file images with hash-verified integrity satisfies the rule.
- ✗
That all evidence be authenticated by a witness.
Why it's wrong here
Authentication under Rule 901 is a distinct prerequisite that every exhibit must meet, but it is not what the best evidence rule demands. The best evidence rule governs how to prove the content of a writing, recording, or photograph—not who proves it or by what kind of testimony. A witness's identification or explanation may authenticate an item, yet if the original or a reliable duplicate is not produced and its absence is not excused, the rule is still violated. Conversely, e-discovery exhibits are routinely admitted with no live sponsor, using system logs, hash values, or business-record affidavits.
- ✗
That only paper copies of digital documents are admissible.
Why it's wrong here
The best evidence rule does not mandate paper copies; for ESI, FRE 1001(d) expressly treats a printout or other readable output as an 'original' if it accurately reflects the stored information. Native digital files are often preferred in e-discovery because they retain metadata, associations, and searchability that paper printouts cannot convey, and Rule 34 permits production in the form ordinarily maintained or a reasonably usable form. The rule's touchstone is accurate reflection of content, not a particular medium, so digital originals are fully admissible.
- ✗
That metadata is preserved in all copies.
Why it's wrong here
The best evidence rule requires producing the original or a reliable duplicate of the content, but it imposes no separate obligation to preserve metadata in every copy. A duplicate under FRE 1003 is admissible even if it lacks system metadata, as long as it accurately reproduces the content and no genuine authenticity or fairness issue arises. Metadata preservation is addressed by other regimes—litigation holds, Rule 34's specified production form, and spoliation analysis—not by the best evidence rule, so omitting metadata does not by itself render a copy non-admissible.
Go deeper
Related to this question
Learn chapter
Legal and Ethical Issues in Digital Forensics
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.