Locard's Exchange Principle in Digital Forensics
An investigator seizes a computer that was involved in a crime. The suspect claims that the evidence was planted. Which forensic principle best helps to refute this claim by demonstrating that the evidence could only have been left by the suspect?
Quick Answer
The correct answer is Locard's exchange principle because it establishes that every contact leaves a trace, meaning the suspect's interaction with the computer—such as typing, accessing files, or connecting peripherals—will inevitably create unique digital artifacts like registry keys, prefetch files, or USB serial numbers. In digital forensics, this principle directly refutes a claim of evidence planting by demonstrating that those artifacts could only have been generated by the suspect's specific actions or device, not by an external party. On the Computer Hacking Forensic Investigator CHFI exam, this concept tests your understanding of how physical-world forensic logic applies to digital evidence, often appearing in scenario-based questions where a suspect denies involvement. A common trap is confusing this with chain of custody, but remember: Locard is about trace transfer, not documentation. Memory tip: "Every contact leaves a trace—even a digital touch leaves a trace."
⚠ Common exam trap
EC-Council often tests whether candidates confuse chain of custody (a procedural safeguard) with Locard's principle (a scientific concept about trace evidence), leading them to pick chain of custody when the question asks about how evidence was left by the suspect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Locard's exchange principle
Locard's exchange principle states that every contact leaves a trace. In digital forensics, this means the suspect's interaction with the computer—such as typing, accessing files, or connecting peripherals—will leave unique digital artifacts (e.g., registry keys, prefetch files, USB device serial numbers, or browser history). By demonstrating that these artifacts could only have been created by the suspect's specific actions or device, the investigator refutes the claim of planting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Locard's exchange principle
Why this is correct
Locard's exchange principle states that every contact leaves a trace, so evidence transferred onto the seized computer demonstrates physical contact between suspect and system. This refutes the planting claim by linking the traceable exchange directly to the suspect's actions.
- ✗
Hearsay rule
Why it's wrong here
The hearsay rule governs admissibility of out-of-court statements offered to prove their truth, so it says nothing about whether the suspect's fingers created the evidence. It is tempting because it concerns statements, but refuting planting requires showing the artefact's origin traces uniquely to the suspect.
- ✗
Best evidence rule
Why it's wrong here
The best evidence rule requires the original writing, recording, or photograph to prove its content, so it addresses document authenticity rather than who created an artefact. It is tempting because it concerns evidence reliability, but demonstrating the suspect alone could leave the trace is a different principle.
- ✗
Chain of custody
Why it's wrong here
Chain of custody documents who handled evidence from seizure to court, proving it was not tampered with after collection; it cannot show the suspect created it before seizure. It is tempting because it rebuts planting allegations, but it addresses post-seizure integrity, not the artefact's origin.
Go deeper
Related to this question
Learn chapter
Overview of Computer Forensics and Investigation Process
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CHFI
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following principles states that when two objects come into contact, there is a transfer of material between them?
easy- A.The best evidence rule
- ✓ B.Locard's exchange principle
- C.The chain of custody
- D.The hearsay rule
Why B: Locard's exchange principle is a foundational concept in forensic science stating that whenever two objects come into contact, there is a transfer of material between them. In digital forensics, this principle applies to the transfer of digital artifacts (e.g., file fragments, metadata, network traces) when systems interact, such as when a suspect's device connects to a server or when data is copied between storage media.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.