CHFI Computer Forensics Fundamentals and Process Practice Question
Which of the following BEST describes Locard's exchange principle as applied to digital forensics?
⚠ Common exam trap
Test-takers frequently confuse procedural best practices (write blockers, chain of custody, order of volatility) with the fundamental theoretical principle of trace evidence exchange, leading them to pick a practical step instead of the conceptual definition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Every contact leaves a trace; an attacker will leave digital evidence on the compromised system.
Locard's exchange principle states that every contact leaves a trace. In digital forensics, this means that when an attacker interacts with a compromised system, they inevitably leave behind digital artifacts such as log entries, modified files, registry changes, or network connection records. Option D correctly captures this core concept as applied to digital forensics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Digital evidence must be collected using a write blocker.
Why it's wrong here
A write blocker is a hardware or software device that intercepts and blocks write commands to an evidence drive during acquisition, preserving the original media's integrity for later court proceedings. This is a procedural safeguard for lawful forensic imaging, not a statement about how criminals leave traces. Locard's principle concerns the theoretical exchange between a perpetrator and a scene, so misidentifying this acquisition tool as the principle confuses methodology with forensic science.
- ✗
The chain of custody must be documented for evidence to be admissible.
Why it's wrong here
Documenting chain of custody is a legal and administrative requirement that establishes who handled evidence, when, where, and under what conditions, so that the evidence can be shown to be authentic and unaltered in court. Admissibility depends on this documentation, but it does not explain why forensic evidence exists. Locard's principle is a scientific axiom about material transfer, not an evidentiary rule, and therefore this option describes a legal process, not the principle itself.
- ✗
Volatile data must be collected before powering off a system.
Why it's wrong here
The order of volatility dictates that highly volatile data, such as RAM contents, open network connections, and running processes, must be captured before the system is powered off because that information disappears instantly on shutdown. This is a best practice predicated on data persistence and preservation, not on the creation of transfer traces. In contrast, Locard's principle predicts that an attacker's interaction will leave some residue on the system; it says nothing about the sequence in which evidence should be collected.
- ✓
Every contact leaves a trace; an attacker will leave digital evidence on the compromised system.
Why this is correct
Locard's exchange principle, originally formulated for physical crime scenes, states that every contact, however slight, leaves a trace, and in digital forensics this means an attacker's activities will invariably generate residual data on the compromised system, such as log entries, altered timestamps, prefetch files, or memory remnants. This transferred principle underlies the entire discipline of digital evidence identification because it gives examiners a theoretical basis for expecting to find attacker artifacts even when the intruder attempts to clean up. It is the only option that directly names the exchange principle rather than a forensic procedure, legal rule, or collection ordering strategy.
Go deeper
Related to this question
Learn chapter
Windows Forensics: File Systems and Artifacts
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.