CHFI Computer Forensics Fundamentals and Process Practice Question
Which of the following is the BEST definition of Locard's exchange principle in computer forensics?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Every contact leaves a trace; an attacker will leave digital traces on a system
Locard's exchange principle states that when a person interacts with a scene, they leave something behind and take something with them. In digital forensics, this means that an attacker will leave traces of their activity on the system (e.g., logs, malware) and may also remove evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Every contact leaves a trace; an attacker will leave digital traces on a system
Why this is correct
Locard's exchange principle holds that every contact between two objects results in a mutual transfer of material; in digital forensics this translates to the unavoidable persistence of digital residues such as filesystem metadata, registry keys, log entries, and volatile memory fragments whenever an attacker interacts with a system. Even if an intruder attempts to cover their tracks, actions like opening a file update its last-accessed timestamp, network connections leave connection logs, and command execution may persist in shell history or process artifacts, making the principle foundational for identifying and reconstructing attacker activity.
- ✗
Chain of custody must be maintained to prove evidence integrity
Why it's wrong here
The chain of custody is an administrative and legal process that documents the seizure, control, transfer, and analysis of evidence to prove its integrity and admissibility in court. While crucial for establishing that digital evidence has not been tampered with, it addresses evidence handling and provenance rather than the physical or digital transfer of trace material that Locard's principle describes. Confusing the two conflates procedural safeguards with a forensic theory about why evidence exists in the first place.
- ✗
The best evidence rule requires original evidence over copies
Why it's wrong here
The best evidence rule, codified in rules like Federal Rule of Evidence 1002, generally requires the original writing, recording, or photograph to prove its content unless a substitution is justified under specific exceptions. In practice, digital evidence is often admitted as duplicates or printouts when authenticity is established, and this rule deals with evidentiary weight and originality, not with the forensic exchange of trace materials. It is a legal admissibility doctrine unrelated to Locard's principle, which explains the creation of digital traces at the time of an event.
- ✗
Digital evidence must be collected in a forensically sound manner to be admissible in court
Why it's wrong here
Collecting digital evidence in a forensically sound manner—using write blockers, hashing original media, and following accepted procedures—ensures that evidence is preserved and remains admissible in court. This concept is oriented toward the examiner's methodology after an incident has occurred, dictating how to protect the evidence's integrity during acquisition and analysis. By contrast, Locard's principle is a descriptive scientific law that explains why traces exist in the first place, regardless of whether those traces are later collected properly; one cannot substitute the other when defining the principle.
Go deeper
Related to this question
Learn chapter
Network Forensics: Logs, Traffic, and Attacks
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.