Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

Which TWO of the following are essential components of a proper chain of custody documentation? (Select TWO.)

⚠ Common exam trap

EC-Council often tests the misconception that technical details about the evidence (like OS version or IP address) are part of chain of custody, when in fact the chain only tracks who handled the evidence and when, not the evidence's configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Date and time of each evidence transfer

Option B is correct because chain of custody documentation must record the date and time of every transfer of evidence, establishing an auditable timeline that proves the evidence was continuously accounted for from seizure to presentation. Option C is correct because each person who handled or transferred the evidence must sign for it, creating individual accountability and showing an unbroken sequence of custody. Together, these entries let investigators demonstrate that the evidence was not tampered with or substituted. Option A is not essential to the chain of custody itself, since the suspect's identity does not establish who controlled the evidence. Option D is irrelevant because the OS version of the suspect's computer is a technical artifact detail, not a custody record. Option E is likewise irrelevant, as the forensic workstation's IP address does not document the handling or transfer of evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The name of the suspect

    Why it's wrong here

    Chain of custody records the movement and handling of evidence, not the identity of the person suspected of the offence. Suspect details belong in the case file or investigation report; custody forms document who collected, transferred, stored and accessed each item, with dates, times and signatures.

  • ✓

    Date and time of each evidence transfer

    Why this is correct

    Recording the date and time of every evidence transfer establishes an auditable timeline proving continuous custody from seizure to presentation. This satisfies the chain of custody requirement by demonstrating that no unaccounted gap permitted tampering.

  • ✓

    Signature of each person who handled the evidence

    Why this is correct

    Each transfer of evidence must be traceable, so every individual who handled the item signs and dates the custody record. This signature creates the unbroken, auditable trail that proves the evidence was not tampered with or substituted between collection and presentation.

  • ✗

    The operating system version of the suspect's computer

    Why it's wrong here

    The operating system version describes the seized machine's configuration, not who handled the evidence or when. Such technical detail belongs in the forensic examination report; chain of custody forms require collector identity, transfer dates, storage location and signatures to prove continuity.

  • ✗

    The IP address of the forensic workstation

    Why it's wrong here

    The forensic workstation's IP address identifies examination equipment, not the custody trail of the evidence itself. Chain of custody documents each transfer between people and locations; workstation addressing belongs in tool validation or examination logs, so it does not establish unbroken custody.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.