Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

A forensic examiner needs to verify the integrity of a forensic image after acquisition. Which of the following methods is the MOST reliable for ensuring the image has not been altered?

⚠ Common exam trap

The CHFI exam often tests the misconception that file metadata or size comparisons are sufficient for integrity verification, when in fact only cryptographic hashing provides content-level assurance against tampering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Calculating and comparing hash values (e.g., MD5 or SHA-1) of the original and the image.

Cryptographic hash functions like MD5 or SHA-1 produce a fixed-size digest that is uniquely tied to the data content. By comparing the hash of the original drive (or its bit-for-bit copy) with the hash of the forensic image, any single bit change in the image will result in a completely different hash value, providing mathematically strong integrity verification. This is the standard method recommended in forensic best practices (e.g., NIST SP 800-86) and is far more reliable than any metadata or size comparison.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Opening the image in a hex editor and visually inspecting the first few bytes.

    Why it's wrong here

    Visual inspection of the first few bytes in a hex editor only verifies the header or file signature, not the entire drive image. Malicious modifications or accidental corruption occurring in later sectors, slack space, or unallocated regions would go completely undetected. This method is also impractical for modern multi-terabyte drives, where reading every byte manually is infeasible, and it lacks the algorithmic rigor of a mathematical integrity check.

  • ✗

    Using the 'dir' command to list files and compare timestamps.

    Why it's wrong here

    The 'dir' command lists file names, sizes, and timestamps from the filesystem metadata, but it does not examine the actual content of the files or the raw disk image. Timestamps and metadata can be altered by an attacker via timestamp manipulation tools (e.g., timestomp), and this method ignores deleted files, slack space, and other data regions. Moreover, comparing timestamps only confirms that metadata matches, not that the underlying data bits are identical to the original.

  • ✓

    Calculating and comparing hash values (e.g., MD5 or SHA-1) of the original and the image.

    Why this is correct

    Calculating and comparing cryptographic hash values (e.g., MD5 or SHA-1) is the forensic standard for verifying that an acquired image is bit-for-bit identical to the original source. A hash function processes the entire data stream and produces a fixed-size digest; any change to even a single bit in the source will produce a drastically different hash value. This provides strong assurance of integrity (though not authenticity) and is the accepted method in forensic imaging tools such as FTK Imager, EnCase, and dd with hash options.

  • ✗

    Comparing file sizes of the original drive and the image.

    Why it's wrong here

    Comparing file sizes only verifies that the logical length of the image matches the original, but it does not ensure that the data content itself is unchanged. A malicious actor can alter data while preserving the exact file size (e.g., swapping bytes or replacing one file with another of equal length), and size comparison would incorrectly pass. Additionally, file size alone does not account for deleted data, slack space, or other low-level regions that may contain critical evidence, making it an inadequate integrity check.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.