CHFI Computer Forensics Fundamentals and Process Practice Question
What is the primary purpose of maintaining a chain of custody during a forensic investigation?
⚠ Common exam trap
EC-Council often tests the distinction between the chain of custody's documentation purpose and other forensic activities like analysis or security, so candidates mistakenly choose options that describe evidence handling steps (e.g., encryption or analysis) rather than the core legal documentation requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To document the handling of evidence from collection to presentation in court
The primary purpose of maintaining a chain of custody is to create a documented, unbroken record of every person who handled the evidence, from the moment it is collected until it is presented in court. This documentation is critical to establish the authenticity and integrity of the evidence, ensuring it has not been tampered with or altered, which is a foundational requirement for admissibility under legal standards like the Federal Rules of Evidence (FRE) 901. Without a proper chain of custody, the evidence can be challenged as inadmissible due to lack of trustworthiness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To document the handling of evidence from collection to presentation in court
Why this is correct
The chain of custody is a legal and administrative record that creates an unbroken chronological log of every individual who collected, handled, transferred, or stored a piece of evidence. This documentation is critical because it demonstrates that the evidence has not been altered, substituted, or contaminated, thereby establishing the authenticity and integrity required for the evidence to be admissible in a court of law. Without a proper chain of custody, the opposing counsel can challenge the evidence's reliability, potentially leading to its exclusion.
- ✗
To reduce the size of evidence for easier storage
Why it's wrong here
This option misidentifies the purpose of chain of custody as a form of data management; in reality, chain of custody is a procedural control for documenting the possession and disposition of an exhibit. Reducing the physical or logical size of evidence is achieved through separate techniques such as file compression, deduplication, or forensic imaging, which are applied to facilitate storage or transmission but do not provide any documentation of who handled the evidence. The chain of custody log remains independent of any size-reduction method and cannot be replaced by it.
- ✗
To analyze the evidence for hidden data
Why it's wrong here
Chain of custody is a foundational record that ensures the evidence is the same item that was originally seized, but it does not involve examining the contents of that evidence. The forensic analysis—such as recovering hidden files, carving deleted data, or extracting metadata—is conducted in a separate analytical phase after the custody trail has been established. Confusing the two would conflate the administrative duty of documenting possession with the technical duty of interpreting the evidence's payload, which are distinct steps in a digital forensic investigation.
- ✗
To encrypt the evidence to prevent unauthorized access
Why it's wrong here
Encryption is a confidentiality control that protects evidence from unauthorized access by making it unreadable without a key, but it is not the function of a chain of custody. The chain of custody is an evidentiary log that records each transfer of custody, the date and time, and the identities of all persons who handled the exhibit, which is independent of whether the evidence is encrypted. While encryption can be used as a supplementary security measure, it cannot fulfill the legal need to demonstrate an unbroken possession history for court admissibility.
Go deeper
Related to this question
Learn chapter
Overview of Computer Forensics and Investigation Process
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
Courseiva writes every CHFI question from scratch — 205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.