Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

Which of the following is the BEST definition of computer forensics?

⚠ Common exam trap

EC-Council often tests the distinction between a narrow technical task (like file recovery or malware scanning) and the full legal and procedural scope of computer forensics, causing candidates to confuse a single step with the entire discipline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application of investigative and analytical techniques to gather and preserve evidence from digital devices suitable for presentation in a court of law.

Computer forensics is fundamentally the application of investigative and analytical techniques to collect, preserve, and analyze digital evidence in a manner that maintains its integrity and admissibility in a court of law. This definition encompasses the entire forensic process, from acquisition through chain of custody to presentation, aligning with the CHFI framework's emphasis on legal and procedural rigor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The application of investigative and analytical techniques to gather and preserve evidence from digital devices suitable for presentation in a court of law.

    Why this is correct

    The application of investigative and analytical techniques to gather and preserve evidence from digital devices suitable for presentation in a court of law is the full-scope definition. It encompasses the entire forensic process: identification, acquisition, preservation, analysis, and documentation while maintaining a strict chain of custody. Every action must be reproducible and defensible in legal proceedings, ensuring that the evidence is authentic, unaltered, and admissible. This distinguishes computer forensics from unrelated practices like malware scanning or network hardening.

  • ✗

    The use of software tools to scan for malware on a computer system.

    Why it's wrong here

    This option describes a specific security operation—typically antivirus or endpoint detection—that identifies malicious software on a live or offline system. It is a reactive or proactive defensive measure focused on detecting and removing threats, not on the systematic investigation of digital evidence. Computer forensics, by contrast, uses specialized tools like EnCase or FTK to acquire disk images, examine file metadata, recover artifacts, and produce an evidence-based narrative for court. Malware analysis may be part of a forensic investigation, but the scan itself is not the discipline.

  • ✗

    The process of recovering deleted files from a hard drive.

    Why it's wrong here

    Recovering deleted files is a single technique used within computer forensics, but it does not capture the investigative and legal dimensions of the field. Forensic data recovery requires write-blockers and cryptographic hashing to ensure the source media is not altered and that recovered files can be authenticated as evidence. Furthermore, forensics involves interpreting the broader context—timeline analysis, file slack, registry entries, and user activity—not just undeleting files. Standard undelete tools often modify the drive and corrupt evidence, making them unsuitable for forensic use.

  • ✗

    The process of securing a computer network from unauthorized access.

    Why it's wrong here

    Securing a network from unauthorized access describes network security or defensive IT administration, which is a proactive measure aimed at preventing incidents. Computer forensics, however, is a reactive investigative discipline applied after an incident occurs, such as a breach, to determine how access was gained, what data was accessed, and who is responsible. Forensic investigators follow legal protocols, preserve evidence with a chain of custody, and produce findings for legal proceedings, whereas security professionals deploy firewalls, intrusion prevention systems, and access controls to deter attacks. The goals, methods, and outcomes are fundamentally different.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.