Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A forensic analyst is examining a hard drive that was seized from a suspect's home. The analyst uses FTK Imager to create a forensic image. After imaging, the analyst computes the MD5 hash of the image and compares it to the hash computed at the scene. The hashes match. What does this confirm?

⚠ Common exam trap

EC-Council often tests the misconception that a matching hash confirms the drive is readable or free from issues like encryption or malware, when in fact it only confirms bit-for-bit integrity of the acquired image.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The image is an exact bit-for-bit copy of the original drive

B is correct because a matching MD5 hash between the image and the original drive confirms that the forensic image is an exact bit-for-bit copy. Hashing algorithms like MD5 produce a unique fixed-size hash value based on the binary content; if two hashes match, the data is identical with no alterations. This validates the integrity of the acquisition process, ensuring that the image is a perfect forensic duplicate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file system is intact and readable

    Why it's wrong here

    A matching hash between source and seized drive only proves that every bit was copied accurately; it says nothing about whether the file system metadata (boot sector, MFT, inodes, journals) is internally coherent or mounted cleanly. For example, a drive with a corrupted directory tree can still be imaged bit-for-bit and produce an identical hash, yet the file system would not be considered intact or readable in a logical sense. Thus hash equality is a necessary but not sufficient condition for file system integrity.

  • ✓

    The image is an exact bit-for-bit copy of the original drive

    Why this is correct

    Forensic acquisition tools such as FTK Imager or dd compute a cryptographic hash (typically MD5, SHA-1, or SHA-256) of both the source drive and the resulting image file; when those values match, the image is an exact bit-for-bit replica of the original media. This hash match assures the examiner that no bytes were altered, dropped, or inserted during acquisition, making it admissible and reliable for analysis. It is precisely why hash verification is the cornerstone of forensic soundness.

  • ✗

    The drive contains malware

    Why it's wrong here

    A cryptographic hash represents a unique fingerprint of the data content, but it does not perform any heuristic or signature-based analysis to detect malicious executables. Even if the image is a perfect bit-for-bit copy, it could contain malware, and conversely, a clean hash match does not exclude infection because hashes are not malware signatures. Determining malware presence requires scanning with antimalware engines, analyzing processes, or manual reverse engineering, none of which are accomplished by hash comparison.

  • ✗

    The drive was not encrypted

    Why it's wrong here

    Hash verification operates at the physical data layer and is agnostic to how the bytes are interpreted, so an encrypted drive imaged with a matching hash remains encrypted in the image. Encryption status is a property of the logical data encoding (e.g., BitLocker, FileVault, LUKS) that can be identified by examining for partition types, headers, or entropy analysis, not by comparing hashes. A bit-for-bit copy of an encrypted disk will have the same hash as the original, but that hash will not indicate whether the plaintext is accessible.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.