C702 - CHFI CH2 EXAM
[LATEST 2025-26] QUESTIONS
AND VERIFIED ANSWERS
100% GUARANTEED PASS
Correct. For more information on this topic see Computer Hacking Forensics Investigator
Module 2 page 119.
Which of the following is not part of the Computer Forensics Investigation Methodology? -
correct answer Testify as an expert defendant
Correct. For more information on this topic see Computer Hacking Forensics Investigator
Module 2 page 135.
Which of the following is not part of the Computer Forensics Investigation Methodology? -
correct answer Evidence Destruction
Correct. For more information on this topic see Computer Hacking Forensics Investigator
Module 2 page 135.
Investigators can immediately take action after receiving a report of a security incident. - correct
answer False
Correct. Investigators cannot jump into action immediately after receiving a complaint or report
of a security incident, but they have to follow a specific protocol that includes gathering of
, plaintiff information, type of incident, and obtaining permission and warrants for taking further
action. For more information on this topic see Computer Hacking Forensics Investigator Module
2 page 132.
Courts call knowledgeable persons to testify to the accuracy of the investigative process. These
people who testify are known as the ________. - correct answer expert witnesses
Correct. As the attorneys, prosecutors, jury members, and others present in a court of law may
be unaware of the technical knowledge regarding the crime, evidence, and losses, the
investigators should approach authorized personnel who could appear in the court as an expert
witness to affirm the accuracy of the process and the data. For more information on this topic
see Computer Hacking Forensics Investigator Module 2 page 194.
A chain of custody is a critical document in the computer forensics investigation process
because the document provides legal validation of appropriate evidence handling. - correct
answer True
Correct. Chain of custody is a legal document that demonstrates the progression of evidence as
it travels from the original evidence location to the forensic laboratory. It is a roadmap that
shows how investigators collected, analyzed, and preserved the evidence. The investigators
need to present this document in court. It ensures accurate auditing of the original data
evidence, imaging of the source media, tracking of the logs, and so on. For more information on
this topic see Computer Hacking Forensics Investigator Module 2 page 164.
Identify the following project, which was launched by the National Institute of Standards and
Technology (NIST), that establishes a "methodology for testing computer forensics software
tools by development of general tool specifications, test procedures, test criteria, test sets, and
test hardware." - correct answer Computer Forensic Tool Testing Project (CFTTP)
Correct. For more information on this topic see Computer Hacking Forensics Investigator
Module 2 page 126.
[LATEST 2025-26] QUESTIONS
AND VERIFIED ANSWERS
100% GUARANTEED PASS
Correct. For more information on this topic see Computer Hacking Forensics Investigator
Module 2 page 119.
Which of the following is not part of the Computer Forensics Investigation Methodology? -
correct answer Testify as an expert defendant
Correct. For more information on this topic see Computer Hacking Forensics Investigator
Module 2 page 135.
Which of the following is not part of the Computer Forensics Investigation Methodology? -
correct answer Evidence Destruction
Correct. For more information on this topic see Computer Hacking Forensics Investigator
Module 2 page 135.
Investigators can immediately take action after receiving a report of a security incident. - correct
answer False
Correct. Investigators cannot jump into action immediately after receiving a complaint or report
of a security incident, but they have to follow a specific protocol that includes gathering of
, plaintiff information, type of incident, and obtaining permission and warrants for taking further
action. For more information on this topic see Computer Hacking Forensics Investigator Module
2 page 132.
Courts call knowledgeable persons to testify to the accuracy of the investigative process. These
people who testify are known as the ________. - correct answer expert witnesses
Correct. As the attorneys, prosecutors, jury members, and others present in a court of law may
be unaware of the technical knowledge regarding the crime, evidence, and losses, the
investigators should approach authorized personnel who could appear in the court as an expert
witness to affirm the accuracy of the process and the data. For more information on this topic
see Computer Hacking Forensics Investigator Module 2 page 194.
A chain of custody is a critical document in the computer forensics investigation process
because the document provides legal validation of appropriate evidence handling. - correct
answer True
Correct. Chain of custody is a legal document that demonstrates the progression of evidence as
it travels from the original evidence location to the forensic laboratory. It is a roadmap that
shows how investigators collected, analyzed, and preserved the evidence. The investigators
need to present this document in court. It ensures accurate auditing of the original data
evidence, imaging of the source media, tracking of the logs, and so on. For more information on
this topic see Computer Hacking Forensics Investigator Module 2 page 164.
Identify the following project, which was launched by the National Institute of Standards and
Technology (NIST), that establishes a "methodology for testing computer forensics software
tools by development of general tool specifications, test procedures, test criteria, test sets, and
test hardware." - correct answer Computer Forensic Tool Testing Project (CFTTP)
Correct. For more information on this topic see Computer Hacking Forensics Investigator
Module 2 page 126.