C702 – CHFI EXAM {L ATEST
2025-26] QUESTIONS AND
VERIFIED ANSWERS 100%
GUARANTEED PASS
Which of the following Federal Rules of Evidence states that the court shall restrict the evidence
to its proper scope and instruct the jury accordingly?
A. Rule 105
B. Rule 102
C. Rule 103
D. Rule 101 - correct answer A. Rule 105
Ref: Module 1, page 47
Which of the following answers refers to a set of methodological procedures and techniques to
identify, gather, preserve, extract, interpret, document, and present evidence from computing
equipment in such a manner that the discovered evidence is acceptable during a legal and/or
administrative proceeding in a court of law?
A. Disaster recovery
B. Computer forensics
C. Incident handling
D. Network analysis - correct answer B. Computer forensics
Ref: Module 1, page 19
Minimizing the tangible and intangible losses to the organization or an individual is considered
an essential computer forensics use.
,A. True
B. False - correct answer A. True
Ref: Module 1, page 19
Cybercrimes can be classified into the following two types of attacks, based on the line of
attack.
A. Fraud and spam
B. Internal and external
C. Phishing and malware - correct answer B. Internal and external
Ref: Module 1, pages 25-26
Espionage, theft of intellectual property, manipulation of records, and Trojan horse attacks are
examples of what?
A. Insider attacks or primary threats
B. Outsider attacks or secondary threats
C. Outsider attacks or primary threats
D. Insider attacks or secondary threats - correct answer A. Insider attacks or primary threats
Ref: Module 1, page 26
External attacks occur when there are inadequate information-security policies and procedures.
A. False
B. True - correct answer B. True
Ref: Module 1, page 26
Which type of cases involve disputes between two parties?
A. Civil
B. Administrative
,C. Investigative
D. Criminal - correct answer A. Civil
Ref: Module 1, page 31
A computer forensic examiner can investigate any crime as long as he or she takes detailed
notes and follows the appropriate processes.
A. True
B. False - correct answer B. False
Ref: Module 1, page 83
________ is the standard investigative model used by the FBI when conducting investigations
against major criminal organizations.
A. Enterprise Theory of Investigation (ETI)
B. Entrepreneur Theory of Investigation
C. Both Enterprise Theory of Investigation (ETI) and Entrepreneur Theory of Investigation -
correct answer A. Enterprise Theory of Investigation (ETI)
Ref: Module 1, page 34
Forensic readiness includes technical and non-technical actions that maximize an organization's
competence to use digital evidence.
A. True
B. False - correct answer A. True
Ref: Module 1, page 64
Which of the following is the process of developing a strategy to address the occurrence of any
security breach in the system or network?
A. Forensic readiness planning
B. Best evidence rule
, C. Security policy
D. Incident response - correct answer D. Incident response
Ref: Module 1, page 70
Codes of ethics are the principles stated to describe the expected behavior of an investigator
while handling a case. Which of the following is not a principle that a computer forensic
investigator must follow?
A. Act with utmost ethical and moral principles.
B. Ensure integrity of the evidence throughout the investigation process.
C. Act in accordance with federal statutes, state statutes, and local laws and policies.
D. Provide personal or prejudiced opinions. - correct answer D. Provide personal or prejudiced
opinions.
Ref: Module 1, page 83
In forensics laws, "authenticating or identifying evidences" comes under which rule?
A. Rule 801
B. Rule 708
C. Rule 608
D. Rule 901 - correct answer D. Rule 901
Ref: Module 1, page 56
What requires companies that offer financial products or services to protect customer
information against security threats?
A. HIPAA
B. FISMA
C. PCI DSS
D. GLBA - correct answer D. GLBA
2025-26] QUESTIONS AND
VERIFIED ANSWERS 100%
GUARANTEED PASS
Which of the following Federal Rules of Evidence states that the court shall restrict the evidence
to its proper scope and instruct the jury accordingly?
A. Rule 105
B. Rule 102
C. Rule 103
D. Rule 101 - correct answer A. Rule 105
Ref: Module 1, page 47
Which of the following answers refers to a set of methodological procedures and techniques to
identify, gather, preserve, extract, interpret, document, and present evidence from computing
equipment in such a manner that the discovered evidence is acceptable during a legal and/or
administrative proceeding in a court of law?
A. Disaster recovery
B. Computer forensics
C. Incident handling
D. Network analysis - correct answer B. Computer forensics
Ref: Module 1, page 19
Minimizing the tangible and intangible losses to the organization or an individual is considered
an essential computer forensics use.
,A. True
B. False - correct answer A. True
Ref: Module 1, page 19
Cybercrimes can be classified into the following two types of attacks, based on the line of
attack.
A. Fraud and spam
B. Internal and external
C. Phishing and malware - correct answer B. Internal and external
Ref: Module 1, pages 25-26
Espionage, theft of intellectual property, manipulation of records, and Trojan horse attacks are
examples of what?
A. Insider attacks or primary threats
B. Outsider attacks or secondary threats
C. Outsider attacks or primary threats
D. Insider attacks or secondary threats - correct answer A. Insider attacks or primary threats
Ref: Module 1, page 26
External attacks occur when there are inadequate information-security policies and procedures.
A. False
B. True - correct answer B. True
Ref: Module 1, page 26
Which type of cases involve disputes between two parties?
A. Civil
B. Administrative
,C. Investigative
D. Criminal - correct answer A. Civil
Ref: Module 1, page 31
A computer forensic examiner can investigate any crime as long as he or she takes detailed
notes and follows the appropriate processes.
A. True
B. False - correct answer B. False
Ref: Module 1, page 83
________ is the standard investigative model used by the FBI when conducting investigations
against major criminal organizations.
A. Enterprise Theory of Investigation (ETI)
B. Entrepreneur Theory of Investigation
C. Both Enterprise Theory of Investigation (ETI) and Entrepreneur Theory of Investigation -
correct answer A. Enterprise Theory of Investigation (ETI)
Ref: Module 1, page 34
Forensic readiness includes technical and non-technical actions that maximize an organization's
competence to use digital evidence.
A. True
B. False - correct answer A. True
Ref: Module 1, page 64
Which of the following is the process of developing a strategy to address the occurrence of any
security breach in the system or network?
A. Forensic readiness planning
B. Best evidence rule
, C. Security policy
D. Incident response - correct answer D. Incident response
Ref: Module 1, page 70
Codes of ethics are the principles stated to describe the expected behavior of an investigator
while handling a case. Which of the following is not a principle that a computer forensic
investigator must follow?
A. Act with utmost ethical and moral principles.
B. Ensure integrity of the evidence throughout the investigation process.
C. Act in accordance with federal statutes, state statutes, and local laws and policies.
D. Provide personal or prejudiced opinions. - correct answer D. Provide personal or prejudiced
opinions.
Ref: Module 1, page 83
In forensics laws, "authenticating or identifying evidences" comes under which rule?
A. Rule 801
B. Rule 708
C. Rule 608
D. Rule 901 - correct answer D. Rule 901
Ref: Module 1, page 56
What requires companies that offer financial products or services to protect customer
information against security threats?
A. HIPAA
B. FISMA
C. PCI DSS
D. GLBA - correct answer D. GLBA