CHFI Computer Forensics Fundamentals and Process Practice Question
Which of the following is the BEST description of Locard's exchange principle as applied to digital forensics?
⚠ Common exam trap
EC-Council often tests whether candidates confuse Locard's exchange principle with general forensic procedures like chain of custody or evidence integrity, so the trap is picking a correct-sounding but non-specific option (B or D) instead of the precise definition of trace transfer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Every contact leaves a trace; the perpetrator will leave digital traces on the crime scene
Locard's exchange principle states that every contact leaves a trace. In digital forensics, this means that when a perpetrator interacts with a system—whether by accessing files, running commands, or connecting to a network—they inevitably leave digital artifacts such as log entries, registry keys, metadata, or network connection records. Option C correctly captures this core concept of trace transfer in the digital domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only original evidence is admissible in court
Why it's wrong here
This option reflects the best evidence rule, a legal doctrine requiring original writings or recordings to prove their content, not Locard's exchange principle. In digital forensics, investigators routinely work on bit-for-bit copies of storage media to avoid altering the original, and courts commonly accept such copies under rules like FRE 1003 unless authenticity is genuinely challenged. Thus, stating that only original evidence is admissible misstates both the law and standard forensic practice, making it incorrect as a description of Locard's principle.
- ✗
Digital evidence must be collected in a manner that preserves its integrity
Why it's wrong here
Preserving the integrity of digital evidence is a foundational procedural requirement involving write blockers, cryptographic hashing, and clean storage media, but it does not articulate the scientific premise that a perpetrator leaves behind trace material. Locard's exchange principle is about the unavoidable creation of traces during any contact—such as file system artifacts, memory remnants, or network logs—while integrity preservation is a later-stage handling standard designed to maintain the evidentiary value of those traces. This option thereby confuses an evidence-handling methodology with the underlying theory of trace generation.
- ✓
Every contact leaves a trace; the perpetrator will leave digital traces on the crime scene
Why this is correct
Locard's exchange principle states that every contact leaves a trace, and in the digital realm this manifests as persistent or volatile artifacts: log entries, deleted file fragments, browser history, network connections, or metadata on the victim's system. When a perpetrator accesses, copies, or exfiltrates data, they necessarily leave digital traces on the target's storage media, memory, or network infrastructure, just as physical contact transfers fibers. Digital forensics operationalizes this principle by identifying and recovering those traces to reconstruct the crime and link the suspect to the scene, making this the correct description.
- ✗
Evidence must be documented with a chain of custody
Why it's wrong here
Chain of custody is a procedural safeguard that creates a documented chronological record of evidence from collection through trial, establishing who handled it and where it was stored. While this assurance of authenticity is essential for admissibility, it has no explanatory power regarding how or why traces are deposited during an offense. Locard's principle is the scientific basis for the existence of trace evidence, whereas chain of custody is a legal accountability mechanism that follows after traces have been discovered and collected.
Go deeper
Related to this question
Learn chapter
Legal and Ethical Issues in Digital Forensics
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.