CFE Evidence and Legal Systems 4 — Questions and Answers
Question 1: When examining digital evidence in a fraud case, what is the first critical step a forensic examiner should take upon receiving a digital device?
- Begin searching file directories for relevant documents
- Create a forensic bit-for-bit image of the original media (Correct answer)
- Connect the device to the internet to check for cloud backups
- Run antivirus software to ensure the device is safe to examine
Correct answer: Create a forensic bit-for-bit image of the original media
Creating a verified forensic image (bit-for-bit copy) preserves the original evidence, allows analysis without risk of altering the original, and supports chain of custody.
Question 2: Under the Federal Rules of Civil Procedure, what term describes the pre-trial process requiring parties to disclose electronically stored information relevant to the case?
- Digital forensics
- Electronic discovery (e-discovery) (Correct answer)
- Metadata harvesting
- Computer-assisted audit techniques
Correct answer: Electronic discovery (e-discovery)
Electronic discovery (e-discovery) governs the identification, preservation, collection, and production of electronically stored information during litigation under FRCP Rule 26.
Question 3: Which type of documentary evidence in a fraud case is most likely to be challenged on authentication grounds?
- Original signed contracts held by the victim company
- Printed screenshots of email conversations (Correct answer)
- Bank statements produced directly by the financial institution
- Audited financial statements with auditor signatures
Correct answer: Printed screenshots of email conversations
Printed screenshots are easily manipulated and lack inherent authentication markers, making them more vulnerable to challenges than documents obtained directly from authoritative sources.
Question 4: In a fraud investigation, 'metadata' from electronic documents can be valuable primarily because it reveals what information?
- The market value of the document's contents
- Data about when a file was created, modified, and by whom (Correct answer)
- Encryption keys used to protect confidential files
- The identity of individuals who printed the document
Correct answer: Data about when a file was created, modified, and by whom
Metadata (data about data) embedded in electronic files can reveal creation dates, modification history, author names, and version history — often crucial for detecting document fraud or backdating.
Question 5: A fraud examiner needs to obtain bank records from a financial institution without tipping off the suspect. Which legal mechanism is most appropriate in a civil investigation?
- Search warrant
- Grand jury subpoena
- Civil subpoena duces tecum (Correct answer)
- Consent form signed by the account holder
Correct answer: Civil subpoena duces tecum
A civil subpoena duces tecum compels third-party institutions to produce records in civil proceedings and can be served directly on the bank without notifying the suspect.
Question 6: The 'best evidence' of a wire transfer in a fraud case would typically be which of the following?
- A witness's testimony about the transfer amount
- The bank's certified records of the wire transaction (Correct answer)
- A summary spreadsheet prepared by the fraud examiner
- The suspect's verbal admission of the transfer
Correct answer: The bank's certified records of the wire transaction
Certified bank records obtained directly from the financial institution constitute the best evidence of a wire transfer's details, with proper foundation and authentication.
Question 7: When a fraud examiner analyzes financial statements, which accounting concept describes the requirement that transactions be recorded in the period they occur, regardless of when cash changes hands?
- Cash basis accounting
- Accrual basis accounting (Correct answer)
- Matching principle
- Revenue recognition principle
Correct answer: Accrual basis accounting
Accrual accounting records revenues when earned and expenses when incurred regardless of cash flow, and manipulating accruals is a common method of financial statement fraud.
When examining digital evidence in a fraud case, what is the first critical step a forensic examiner should take upon receiving a digital device?