CHFI Computer Forensics Fundamentals and Process Practice Question
A forensic analyst is examining a hard drive that was seized from a suspect's home. The analyst uses FTK Imager to create a forensic image. After imaging, the analyst computes the MD5 hash of the image and compares it to the hash computed at the scene. The hashes match. What does this confirm?
⚠ Common exam trap
EC-Council often tests the misconception that a matching hash confirms the drive is readable or free from issues like encryption or malware, when in fact it only confirms bit-for-bit integrity of the acquired image.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The image is an exact bit-for-bit copy of the original drive
B is correct because a matching MD5 hash between the image and the original drive confirms that the forensic image is an exact bit-for-bit copy. Hashing algorithms like MD5 produce a unique fixed-size hash value based on the binary content; if two hashes match, the data is identical with no alterations. This validates the integrity of the acquisition process, ensuring that the image is a perfect forensic duplicate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file system is intact and readable
Why it's wrong here
A matching hash between source and seized drive only proves that every bit was copied accurately; it says nothing about whether the file system metadata (boot sector, MFT, inodes, journals) is internally coherent or mounted cleanly. For example, a drive with a corrupted directory tree can still be imaged bit-for-bit and produce an identical hash, yet the file system would not be considered intact or readable in a logical sense. Thus hash equality is a necessary but not sufficient condition for file system integrity.
- ✓
The image is an exact bit-for-bit copy of the original drive
Why this is correct
Forensic acquisition tools such as FTK Imager or dd compute a cryptographic hash (typically MD5, SHA-1, or SHA-256) of both the source drive and the resulting image file; when those values match, the image is an exact bit-for-bit replica of the original media. This hash match assures the examiner that no bytes were altered, dropped, or inserted during acquisition, making it admissible and reliable for analysis. It is precisely why hash verification is the cornerstone of forensic soundness.
- ✗
The drive contains malware
Why it's wrong here
A cryptographic hash represents a unique fingerprint of the data content, but it does not perform any heuristic or signature-based analysis to detect malicious executables. Even if the image is a perfect bit-for-bit copy, it could contain malware, and conversely, a clean hash match does not exclude infection because hashes are not malware signatures. Determining malware presence requires scanning with antimalware engines, analyzing processes, or manual reverse engineering, none of which are accomplished by hash comparison.
- ✗
The drive was not encrypted
Why it's wrong here
Hash verification operates at the physical data layer and is agnostic to how the bytes are interpreted, so an encrypted drive imaged with a matching hash remains encrypted in the image. Encryption status is a property of the logical data encoding (e.g., BitLocker, FileVault, LUKS) that can be identified by examining for partition types, headers, or entropy analysis, not by comparing hashes. A bit-for-bit copy of an encrypted disk will have the same hash as the original, but that hash will not indicate whether the plaintext is accessible.
Go deeper
Related to this question
Learn chapter
Forensic Tools and Laboratory Setup
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.