CHFI Computer Forensics Fundamentals and Process Practice Question
Locard's exchange principle is fundamental to forensic science. How does this principle apply to computer forensics?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Every action on a digital device leaves some trace of evidence.
Locard's principle states that every contact leaves a trace; in digital forensics, this translates to digital traces left behind when a system is accessed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Every action on a digital device leaves some trace of evidence.
Why this is correct
In digital forensics, Locard's exchange principle translates to the fact that any user or system action modifies the state of the device: opening a file updates access timestamps, running a program creates process artifacts, and network activity generates logs. These traces can reside in filesystem metadata, application history, event logs, unallocated space, or even slack space. Anti-forensic tools themselves leave traces—such as installation footprints, modified timestamps, or leftover logs—so a determined actor cannot act without leaving some recoverable evidence.
- ✗
Digital evidence is always volatile and must be preserved immediately.
Why it's wrong here
Digital evidence is not uniformly volatile; it exists on a spectrum. While RAM, live network connections, and current process listings disappear when power is lost, persistent storage like hard disks, solid-state drives (with caveats about TRIM/garbage collection), and optical media can retain data for years. The statement incorrectly equates the urgent need to capture fleeting live-state data with all digital evidence, when in practice examiners use an order of volatility to prioritize collection based on each data type's persistence.
- ✗
Evidence must be collected within 24 hours.
Why it's wrong here
There is no forensic or legal rule that mandates evidence collection within 24 hours; persistence depends on the storage medium, environmental conditions, and retention policies. A powered-down hard drive may preserve data indefinitely, whereas unlogged memory or network flows can be lost in seconds. Legal processes—such as obtaining a warrant, issuing a preservation order, or negotiating with a custodian—can take longer than a day and do not automatically invalidate later collection. This option mistakes a practical guideline for time-sensitive volatile evidence as a universal, rigid deadline.
- ✗
Only physical evidence, such as fingerprints, can be left at a crime scene.
Why it's wrong here
Locard's principle is not limited to physical trace evidence like fingerprints or DNA; every contact with a digital system creates intangible traces as well. Browsing leaves history alongside cookies, connecting a USB device writes registry entries and device artifacts, and sending an email records timestamps and routing metadata in multiple servers. These digital traces are often more probative at a cybercrime scene than any physical object, so restricting evidence to physical forms ignores the core of modern forensic investigation.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.