
CFE exam practice question: daily practice for the Certified Fraud Examiner (CFE) exam — domain: Law.
Question
An internal investigator finds a company laptop suspected of containing evidence of embezzlement. To preserve the laptop for potential legal proceedings, which action best preserves the chain of custody and admissibility of digital evidence?
Show the answer and explanation
Correct answer: A. Create a forensically sound bit-for-bit image of the drive using a hardware write-blocker, compute and record cryptographic hashes, and document every transfer in a chain-of-custody log.
Option 1 is best because a forensically sound, bit-for-bit image created with a hardware write-blocker prevents alteration of original media. Recording cryptographic hashes and documenting every transfer preserves the integrity and audit trail courts require for admissibility. Option 2 is inferior because removing and transporting an unsealed drive and copying files risks contamination and undocumented changes, breaking the chain of custody. Option 3 is improper because interacting with the live system and exporting files can alter metadata and evidence, undermining reliability. Option 4 documents appearance but fails to capture a verifiable forensic image and hash, leaving the original unanalyzed and potentially contested in court.
Want more practice?
Prepare for the Certified Fraud Examiner (CFE) exam with New Material: CFE 2026 Prep Bundle.
