CHFI Computer Forensics Fundamentals and Process Practice Question
Which of the following is a key requirement for digital evidence to be considered admissible in court?
⚠ Common exam trap
EC-Council often tests the misconception that procedural steps like write-blocking or law enforcement involvement are legal requirements, when in fact the core admissibility criterion is the ability to prove authenticity and integrity through verifiable means like hash values and chain of custody documentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The evidence must be authentic and its integrity must be verifiable
Digital evidence must be authentic and its integrity verifiable to meet the legal standard of admissibility, as established by rules such as the Federal Rules of Evidence (FRE 901) and the Daubert standard. Authentication requires proving that the evidence is what it claims to be, typically through a hash value (e.g., MD5, SHA-1, or SHA-256) computed before and after analysis to ensure no tampering occurred. Without verifiable integrity, the evidence could be challenged as altered, making it inadmissible regardless of how it was collected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The evidence must be authentic and its integrity must be verifiable
Why this is correct
To be admissible, digital evidence must be authenticated — the proponent must show it is what it claims to be — and its integrity must be verifiable through a demonstrable chain of custody and cryptographic hash values. Courts require these to ensure the evidence has not been altered or corrupted from the time of acquisition to presentation, as a failure to prove authenticity or integrity undermines its reliability and relevance.
- ✗
The evidence must have been collected by a law enforcement officer
Why it's wrong here
Digital evidence does not require collection by a law enforcement officer to be admissible; qualified forensic examiners, private-sector incident responders, or other competent professionals may lawfully collect and handle evidence. The controlling standard is whether the collector was competent and utilized reliable methods, not whether they hold a law enforcement title, making this option an overstatement of the evidentiary requirement.
- ✗
The evidence must be stored on a write-blocked device
Why it's wrong here
Write-blocking is a best practice for forensic acquisition to preserve the evidential integrity of a storage device, but it is not a legal requirement for admissibility. Evidence can be admitted even if a write-blocker was not used, provided the examiner can demonstrate that the evidence's integrity was nonetheless maintained through hash verification and proper controls; the lack of a write-blocker alone does not render evidence inadmissible.
- ✗
The evidence must be encrypted to ensure confidentiality
Why it's wrong here
Encryption is not a legal prerequisite for the admissibility of digital evidence; confidentiality concerns are separate from the authenticity and integrity standards that govern admission. Evidence may be unencrypted and still be fully admissible if its authenticity is established, while encrypted evidence can still be excluded if its integrity cannot be verified or it fails authentication, so this option confuses security best practices with evidentiary requirements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.