Courseiva

Locard's Exchange Principle in Digital Forensics

An investigator seizes a computer that was involved in a crime. The suspect claims that the evidence was planted. Which forensic principle best helps to refute this claim by demonstrating that the evidence could only have been left by the suspect?

Quick Answer

The correct answer is Locard's exchange principle because it establishes that every contact leaves a trace, meaning the suspect's interaction with the computer—such as typing, accessing files, or connecting peripherals—will inevitably create unique digital artifacts like registry keys, prefetch files, or USB serial numbers. In digital forensics, this principle directly refutes a claim of evidence planting by demonstrating that those artifacts could only have been generated by the suspect's specific actions or device, not by an external party. On the Computer Hacking Forensic Investigator CHFI exam, this concept tests your understanding of how physical-world forensic logic applies to digital evidence, often appearing in scenario-based questions where a suspect denies involvement. A common trap is confusing this with chain of custody, but remember: Locard is about trace transfer, not documentation. Memory tip: "Every contact leaves a trace—even a digital touch leaves a trace."

⚠ Common exam trap

EC-Council often tests whether candidates confuse chain of custody (a procedural safeguard) with Locard's principle (a scientific concept about trace evidence), leading them to pick chain of custody when the question asks about how evidence was left by the suspect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Locard's exchange principle

Locard's exchange principle states that every contact leaves a trace. In digital forensics, this means the suspect's interaction with the computer—such as typing, accessing files, or connecting peripherals—will leave unique digital artifacts (e.g., registry keys, prefetch files, USB device serial numbers, or browser history). By demonstrating that these artifacts could only have been created by the suspect's specific actions or device, the investigator refutes the claim of planting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Locard's exchange principle

    Why this is correct

    Locard's exchange principle states that every contact leaves a trace, so evidence transferred onto the seized computer demonstrates physical contact between suspect and system. This refutes the planting claim by linking the traceable exchange directly to the suspect's actions.

  • ✗

    Hearsay rule

    Why it's wrong here

    The hearsay rule governs admissibility of out-of-court statements offered to prove their truth, so it says nothing about whether the suspect's fingers created the evidence. It is tempting because it concerns statements, but refuting planting requires showing the artefact's origin traces uniquely to the suspect.

  • ✗

    Best evidence rule

    Why it's wrong here

    The best evidence rule requires the original writing, recording, or photograph to prove its content, so it addresses document authenticity rather than who created an artefact. It is tempting because it concerns evidence reliability, but demonstrating the suspect alone could leave the trace is a different principle.

  • ✗

    Chain of custody

    Why it's wrong here

    Chain of custody documents who handled evidence from seizure to court, proving it was not tampered with after collection; it cannot show the suspect created it before seizure. It is tempting because it rebuts planting allegations, but it addresses post-seizure integrity, not the artefact's origin.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which of the following principles states that when two objects come into contact, there is a transfer of material between them?

easy
  • A.The best evidence rule
  • ✓ B.Locard's exchange principle
  • C.The chain of custody
  • D.The hearsay rule

Why B: Locard's exchange principle is a foundational concept in forensic science stating that whenever two objects come into contact, there is a transfer of material between them. In digital forensics, this principle applies to the transfer of digital artifacts (e.g., file fragments, metadata, network traces) when systems interact, such as when a suspect's device connects to a server or when data is copied between storage media.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.