Courseiva
Computer Forensics Fundamentals and ProcesseasyMultiple ChoiceObjective-mapped

CHFI Computer Forensics Fundamentals and Process Practice Question

What is the PRIMARY purpose of a chain of custody document in a forensic investigation?

⚠ Common exam trap

EC-Council often tests the distinction between the chain of custody (which tracks handling history) and the search warrant (which grants legal authority), causing candidates to mistakenly choose the authorization option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To provide a chronological record of who handled the evidence, when, and why.

The chain of custody document is the foundational record that ensures evidence integrity and admissibility in court. Its primary purpose is to create a chronological, unbroken log of every person who handled the evidence, the exact time and date of each transfer, and the reason for the transfer. This directly supports the legal requirement to prove that the evidence has not been tampered with or altered from the moment of seizure to its presentation in court.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To provide a chronological record of who handled the evidence, when, and why.

    Why this is correct

    The chain of custody document exists to create a verifiable, chronological account of every individual who came into possession of evidence, along with the specific timestamps and reasons for each transfer. This unbroken record is what establishes the item's integrity and continuity from collection through courtroom presentation, assuring the fact-finder that the evidence was not altered, substituted, or contaminated. Without a defensible chain of custody, even forensically sound evidence may be ruled inadmissible.

  • To document the tools used during the investigation.

    Why it's wrong here

    Documenting the tools used during an investigation is a matter of forensic methodology, typically captured in an examination report that names workstations, software versions, and hash libraries for reproducibility and reliability testing. The chain of custody, in contrast, does not catalogue instruments; it records the physical possession and transfer of the evidence item itself, irrespective of the technology used to analyze it. Confusing the two conflates the scientific process of analysis with the independent legal requirement of maintaining a clear custody timeline.

  • To list all the files found on the suspect's computer.

    Why it's wrong here

    Listing all files found on a suspect's computer is an artifact of the analytical process, generally memorialized in a forensic examination report or an evidence worksheet, not in the custody record. The chain of custody merely tracks the item's custody status, such as recovered, moved, or stored, and never attempts to enumerate the files it contains, because doing so would mix case conclusions with custodial facts. It is the unbroken custody documentation that later makes a file listing credible by proving the underlying source data was not tampered with.

  • To authorize the search and seizure of digital evidence.

    Why it's wrong here

    Search-and-seizure authorization is a separate legal prerequisite derived from a warrant, consent, or statutory exception, and is documented in the application, warrant, or consent form rather than in a chain of custody record. The chain-of-custody document only comes into play after lawful seizure occurs, acting as the evidentiary trail from that moment forward. While a custodian's testimony can help prove how evidence was recovered, the custody document itself never grants or records the authority to seize the evidence.

Go deeper

Related to this question

About these practice questions

One of 205 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.