Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

Which TWO of the following are examples of circumstantial evidence in a digital forensics investigation? (Select TWO)

⚠ Common exam trap

EC-Council often tests the distinction between direct and circumstantial evidence by presenting seemingly conclusive items (like a video or confession) as traps, leading candidates to overlook that circumstantial evidence requires inference, not direct observation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Metadata showing a file was created on the suspect's computer during the incident timeframe

Option C is correct because file metadata (such as MAC times — Modified, Accessed, Created/Changed timestamps) is generated automatically by the file system and does not directly prove the suspect performed the criminal act; it only supports an inference that the file was created on the suspect's machine during the incident window, which is the essence of circumstantial evidence. Option E is correct because server logs recording the suspect's IP address at the time of the incident are system-generated artifacts that, by themselves, only suggest a connection between the suspect's address and the event; they require inference (and corroboration, since IP addresses can be spoofed or shared via NAT) to link the suspect to the crime, making them circumstantial. Option A is not circumstantial but direct testimonial evidence, since the witness claims firsthand observation of the crime. Option B is direct evidence because the recording itself shows the suspect performing the incriminating act of typing the password. Option D is direct evidence as a signed confession is an admission by the suspect of the act itself, not an inferential link.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A witness testifying they saw the suspect commit the crime

    Why it's wrong here

    An eyewitness account of the suspect committing the crime is direct evidence of the act itself; the witness testifies to having personally observed the essential conduct, so the fact in issue is established through sensory perception. Unlike circumstantial evidence, no chain of reasoning from a collateral fact to the material fact is required.

  • ✗

    A video recording of the suspect typing a password

    Why it's wrong here

    Video footage that unmistakably records the suspect typing a password is direct evidence because it visually captures the specific act being litigated; it is a contemporaneous recording of the event itself, rendering inference unnecessary. Even if the password is not visible on screen, the physical act of typing is the relevant conduct, provided the recording clearly shows it.

  • ✓

    Metadata showing a file was created on the suspect's computer during the incident timeframe

    Why this is correct

    File-creation metadata, such as $STANDARD_INFORMATION timestamps, only records when an entry was added to the filesystem; it reveals nothing about who executed the creation or whether the account owner was present. Demonstrating the suspect created the file requires inferring identity from custody, login records, and behavioral patterns, so it is circumstantial evidence that supports a conclusion only after reasoning.

  • ✗

    A signed confession from the suspect

    Why it's wrong here

    A signed confession is direct evidence because it is an explicit, self-incriminating statement by the suspect acknowledging commission of the crime; it asserts the ultimate fact directly without needing any inference. The trier of fact assesses authenticity and voluntariness, but does not have to piece together intermediate facts to reach guilt.

  • ✓

    Server logs showing the suspect's IP address connected at the time of the incident

    Why this is correct

    Server logs linking an IP address assigned to the suspect to a session at the incident time are circumstantial because an IP address is a network identifier, not a human identity. The inference that the suspect was the user may be weakened by dynamic addressing, NAT, proxies, or remote access, so the log does not directly prove the suspect's physical or mental involvement.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.