CHFI Computer Forensics Fundamentals and Process Practice Question
Which THREE of the following correctly describe the rules of evidence as applied to digital forensics? (Select three.)
⚠ Common exam trap
The CHFI exam often tests the misconception that hearsay evidence is always inadmissible, but in digital forensics, server logs and automated records frequently qualify under hearsay exceptions, making Option C a trap for those who do not know the exceptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evidence must be relevant to the case and obtained through lawful means
Option A is correct because the fundamental rules of evidence require that any item, including digital artifacts, be both relevant to the matter at hand and collected through lawful means (e.g., valid warrants, consent, or legal exceptions), otherwise it can be excluded. Option D is correct because the evidence must be complete and not misleading — partial or selectively presented data (such as a truncated log or an edited image) can create a false impression and is therefore inadmissible or subject to challenge. Option E is correct because digital evidence must be authentic (shown to be what it purports to be) and its integrity must be verifiable, typically through hash values (e.g., MD5, SHA-256) and a documented chain of custody. Option B is incorrect because circumstantial evidence is generally admissible in both criminal and civil cases, including digital forensics, and is often used to infer facts when direct evidence is unavailable. Option C is incorrect because hearsay is not always inadmissible; numerous exceptions and exemptions exist (e.g., business records, excited utterances, and machine-generated records), and digital evidence frequently falls under such exceptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Evidence must be relevant to the case and obtained through lawful means
Why this is correct
Relevance and lawful acquisition are fundamental because evidence must have probative value under Federal Rule of Evidence 401 and be obtained without violating constitutional protections. If evidence is seized via an unlawful search or warrantless procedure, it may be suppressed under the exclusionary rule as 'fruit of the poisonous tree,' even if otherwise probative. This dual requirement ensures that digital forensics examinations do not rely on tainted data that could undermine the integrity of the entire case.
- ✗
Circumstantial evidence is not allowed in digital forensics cases
Why it's wrong here
Circumstantial evidence is fully permissible in digital forensics cases and is often the primary form of evidence available. Unlike direct evidence, which proves a fact without inference, circumstantial evidence such as login timestamps, file access logs, or metadata patterns requires a reasoned inference to connect it to the incident. Courts routinely admit such evidence as long as it is relevant and reliable, so this statement is incorrect because it conflates a lower degree of certainty with inadmissibility.
- ✗
Hearsay evidence is always inadmissible in court
Why it's wrong here
Hearsay is not always inadmissible; the Federal Rules of Evidence carve out numerous exceptions, and computer-generated records often avoid hearsay classification entirely. Automated log files, sensor data, or database entries are not 'statements' made by a declarant for hearsay purposes, and if they are, they may qualify under the business records exception if regularly kept and relied upon. This statement is wrong because it ignores these established exceptions and the distinction between human-generated and machine-generated records, which are commonly admitted in digital forensics.
- ✓
The evidence must be complete and not misleading
Why this is correct
Completeness is a core requirement because evidence that tells only part of the story can be misleading and therefore prejudicial under Rule 403. The rule of completeness, codified in Federal Rule of Evidence 106, allows a party to introduce the remainder of a writing or recording to provide context and prevent distortion. In digital forensics, this means presenting the full timeline, relevant file fragments, and logs rather than isolated artifacts that could imply a false sequence of events, ensuring the trier of fact receives an accurate picture.
- ✓
Evidence must be authentic and its integrity must be verifiable
Why this is correct
Authentication and verifiable integrity are essential to show that digital evidence is what it purports to be and has not been altered since collection. Under Rule 901, this typically demands a foundational showing, such as cryptographic hash values matching the original, a documented chain of custody, and forensic imaging tools that preserve bit-for-bit copies. Without such verification, the evidence may be excluded as unreliable, because digital data can be trivially modified and any unexplained change could compromise its probative value.
Go deeper
Related to this question
Learn chapter
Evidence Handling and Chain of Custody
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.