EnCE Legal Procedures 2 — Questions and Answers
Question 1: Which legal standard must investigators meet when seeking a search warrant for digital evidence in the United States?
- Reasonable suspicion
- Probable cause (Correct answer)
- Preponderance of evidence
- Clear and convincing evidence
Correct answer: Probable cause
The Fourth Amendment requires probable cause supported by an oath or affirmation before a judge can issue a search warrant.
Question 2: Under the Electronic Communications Privacy Act (ECPA), which category of stored electronic communications requires a search warrant to compel disclosure from a service provider?
- Email headers older than 180 days
- Unopened email stored less than 180 days (Correct answer)
- Subscriber account information
- IP address logs
Correct answer: Unopened email stored less than 180 days
ECPA requires a search warrant for unopened electronic communications stored for 180 days or fewer, providing the strongest protection.
Question 3: What is the primary purpose of a 'chain of custody' document in digital forensics?
- To record the hash values of evidence
- To track all persons who accessed or handled evidence (Correct answer)
- To document the forensic software tools used
- To log the acquisition start and end times
Correct answer: To track all persons who accessed or handled evidence
Chain of custody documentation tracks every person who handled the evidence, ensuring its integrity and admissibility in court.
Question 4: A forensic examiner is subpoenaed to testify about findings in a civil case. In what capacity is the examiner most likely testifying?
- Fact witness
- Character witness
- Expert witness (Correct answer)
- Adverse witness
Correct answer: Expert witness
A forensic examiner with specialized knowledge testifies as an expert witness, allowed to offer opinions beyond direct observations.
Question 5: Which doctrine allows evidence obtained in violation of the Fourth Amendment to be excluded from trial?
- The fruit of the poisonous tree doctrine
- The exclusionary rule (Correct answer)
- The plain view doctrine
- The inevitable discovery doctrine
Correct answer: The exclusionary rule
The exclusionary rule prohibits the use of illegally obtained evidence in a criminal trial to deter unlawful police conduct.
Question 6: What must be true for the 'plain view' doctrine to justify a warrantless seizure of digital evidence found during a lawful search?
- The officer must have a general warrant covering all devices
- The incriminating nature of the evidence must be immediately apparent (Correct answer)
- The evidence must be physically visible without opening any files
- The suspect must be present at the time of seizure
Correct answer: The incriminating nature of the evidence must be immediately apparent
Under plain view, the incriminating character of the item must be immediately apparent to the officer who lawfully observed it.
Question 7: In federal court, which rule governs the authentication requirements for digital evidence?
- Federal Rule of Evidence 702
- Federal Rule of Evidence 901 (Correct answer)
- Federal Rule of Evidence 403
- Federal Rule of Evidence 803
Correct answer: Federal Rule of Evidence 901
FRE 901 requires that evidence be authenticated or identified as what the proponent claims it to be before admission.
Which legal standard must investigators meet when seeking a search warrant for digital evidence in the United States?