CHFI Computer Forensics Fundamentals and Process Practice Question
Which of the following is an example of Locard's Exchange Principle as applied to digital forensics?
⚠ Common exam trap
EC-Council often tests the misconception that any security tool or data protection mechanism (like encryption or firewalls) is an example of Locard's Exchange Principle, when in fact the principle specifically requires evidence of a transfer or contact trace, not a barrier or lack of access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A suspect's computer contains log files showing they accessed a server
Locard's Exchange Principle states that every contact leaves a trace. In digital forensics, this translates to the idea that when a system interacts with another, digital artifacts (such as log entries, registry keys, or network connection records) are created. Option A is correct because the log files on the suspect's computer are a direct trace of the contact between the suspect's system and the server, demonstrating the principle in a digital context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A suspect's computer contains log files showing they accessed a server
Why this is correct
Locard's exchange principle holds that any contact leaves traces; a network connection from a suspect's computer to a server is such a contact. The log files on the suspect's system are digital remnants of that interaction, demonstrating that the access transferred data and left artifacts on both endpoints. These artifacts are analogous to physical trace evidence, making this a valid example of the principle.
- ✗
A hard drive is encrypted and cannot be read
Why it's wrong here
Encryption at rest is a data-protection mechanism, not a consequence of interaction between two entities. Although an encrypted hard drive may be impossible to read, the encryption itself is a pre-existing state or deliberate countermeasure, not a trace transferred during a procedure. The principle concerns trace evidence exchanged during contact, so the inability to decode data is irrelevant to establishing or refuting Locard's exchange.
- ✗
A firewall blocks all incoming traffic from a specific IP address
Why it's wrong here
A firewall rule that drops packets from a specific IP is an operational security control, not a record of any physical or digital exchange. The rule is applied based on preconfigured policy, and its action does not create or preserve trace evidence; rather, it prevents a connection from being made. Locard's principle requires actual contact and transfer of material, which is absent when traffic is blocked before any transaction occurs.
- ✗
A write blocker prevents data from being written to a drive
Why it's wrong here
A write blocker is a forensic tool intentionally interposed to maintain the integrity of a storage device; it functions by preventing any writes, but it does not itself acquire or transfer evidence. Its use is a procedure for preserving the evidentiary condition of data, not a trace left by an event. The principle would be exemplified by data transfers occurring between devices, not by the protective hardware used during examination.
Go deeper
Related to this question
Learn chapter
Windows Forensics: File Systems and Artifacts
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.