Direct vs Circumstantial Evidence in Computer Forensics
Which TWO of the following are considered types of evidence under the rules of evidence?
Quick Answer
The answer is direct and circumstantial evidence, as these are the two primary types of evidence recognized under the rules of evidence in computer forensics. Direct evidence directly proves a fact, such as a surveillance video showing an unauthorized login, while circumstantial evidence requires inference, like log files showing a user’s credentials were used at the time of an intrusion. On the Computer Hacking Forensic Investigator CHFI exam, this distinction tests your understanding of foundational legal concepts that govern how digital evidence is classified and presented in court. A common trap is confusing hearsay or best evidence rules—which are procedural rules, not evidence types—with actual categories of evidence. To remember this, think of the mnemonic “DC” for Direct and Circumstantial, and that hearsay and best evidence are “rules, not types.”
⚠ Common exam trap
EC-Council CHFI often tests the distinction between a rule of evidence (like the Best Evidence Rule) and a type of evidence (direct or circumstantial), causing candidates to confuse procedural rules with classification categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Direct evidence
Direct evidence (Option B) is a type of evidence under the rules of evidence because it directly proves a fact without requiring any inference or presumption. In computer forensics, this could include a log entry showing an unauthorized login from a specific IP address at a specific time, which directly proves the fact of access. The rules of evidence recognize direct evidence as primary proof that stands on its own.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Best evidence rule
Why it's wrong here
Best evidence rule is a legal principle, not a type of evidence.
- ✓
Direct evidence
Why this is correct
Direct evidence directly proves a fact without inference.
- ✓
Circumstantial evidence
Why this is correct
Circumstantial evidence requires inference to connect to a fact.
- ✗
Hearsay evidence
Why it's wrong here
Hearsay is a rule about out-of-court statements, not a type of evidence.
- ✗
Exculpatory evidence
Why it's wrong here
Exculpatory evidence is evidence favorable to the defendant, but it is a category based on effect, not a type under the rules.
Go deeper
Related to this question
Learn chapter
Overview of Computer Forensics and Investigation Process
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
Courseiva writes every CHFI question from scratch — 205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CHFI
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are considered types of evidence under the rules of evidence? (Choose three.)
hard- A.Corroborating evidence
- B.Best evidence
- ✓ C.Circumstantial evidence
- ✓ D.Direct evidence
- ✓ E.Hearsay evidence
Why C: Circumstantial evidence is a recognized type of evidence under the rules of evidence because it relies on an inference to connect a fact to a conclusion, rather than directly proving the fact. In digital forensics, circumstantial evidence might include log entries showing a user logged in at the time of an incident, which indirectly suggests involvement. It is admissible as long as the chain of inferences is reasonable and supported by other facts.
Variation 2. Which TWO of the following are considered forms of evidence under the rules of evidence? (Select two.)
medium- A.Illegally obtained evidence
- B.Hearsay evidence
- ✓ C.Circumstantial evidence
- D.Opinion evidence
- ✓ E.Direct evidence
Why C: Circumstantial evidence is a recognized form of evidence under the rules of evidence because it allows a fact-finder to infer a fact from other established facts, even without direct witness testimony. In digital forensics, this is critical when reconstructing user activity from log files, file metadata, or network traffic patterns that indirectly prove an action occurred.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.