CHFI Computer Forensics Fundamentals and Process Practice Question
Which TWO of the following are essential components of a proper chain of custody documentation? (Select TWO.)
⚠ Common exam trap
EC-Council often tests the misconception that technical details about the evidence (like OS version or IP address) are part of chain of custody, when in fact the chain only tracks who handled the evidence and when, not the evidence's configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Date and time of each evidence transfer
Option B is correct because chain of custody documentation must record the date and time of every transfer of evidence, establishing an auditable timeline that proves the evidence was continuously accounted for from seizure to presentation. Option C is correct because each person who handled or transferred the evidence must sign for it, creating individual accountability and showing an unbroken sequence of custody. Together, these entries let investigators demonstrate that the evidence was not tampered with or substituted. Option A is not essential to the chain of custody itself, since the suspect's identity does not establish who controlled the evidence. Option D is irrelevant because the OS version of the suspect's computer is a technical artifact detail, not a custody record. Option E is likewise irrelevant, as the forensic workstation's IP address does not document the handling or transfer of evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The name of the suspect
Why it's wrong here
Chain of custody records the movement and handling of evidence, not the identity of the person suspected of the offence. Suspect details belong in the case file or investigation report; custody forms document who collected, transferred, stored and accessed each item, with dates, times and signatures.
- ✓
Date and time of each evidence transfer
Why this is correct
Recording the date and time of every evidence transfer establishes an auditable timeline proving continuous custody from seizure to presentation. This satisfies the chain of custody requirement by demonstrating that no unaccounted gap permitted tampering.
- ✓
Signature of each person who handled the evidence
Why this is correct
Each transfer of evidence must be traceable, so every individual who handled the item signs and dates the custody record. This signature creates the unbroken, auditable trail that proves the evidence was not tampered with or substituted between collection and presentation.
- ✗
The operating system version of the suspect's computer
Why it's wrong here
The operating system version describes the seized machine's configuration, not who handled the evidence or when. Such technical detail belongs in the forensic examination report; chain of custody forms require collector identity, transfer dates, storage location and signatures to prove continuity.
- ✗
The IP address of the forensic workstation
Why it's wrong here
The forensic workstation's IP address identifies examination equipment, not the custody trail of the evidence itself. Chain of custody documents each transfer between people and locations; workstation addressing belongs in tool validation or examination logs, so it does not establish unbroken custody.
Go deeper
Related to this question
Learn chapter
Evidence Handling and Chain of Custody
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.