CHFI Computer Forensics Fundamentals and Process Practice Question
A forensic investigator uses FTK Imager to create a forensic image of a suspect's laptop. The acquisition generates both an E01 file and a corresponding hash file. Which statement accurately describes the integrity verification process in FTK Imager?
⚠ Common exam trap
Test-takers frequently assume hash verification requires an external file or separate tool, but FTK Imager embeds the hash directly in the E01 file, making verification a built-in feature that does not rely on external databases or post-acquisition computation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The image file includes embedded hash values that can be verified later to ensure data integrity
FTK Imager embeds hash values (MD5 and SHA1) directly into the E01 file during acquisition. These embedded hashes can be verified later by FTK Imager or compatible tools to confirm that the image has not been altered, ensuring data integrity without relying on an external hash file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The hash is computed only when the image is mounted for analysis, not during acquisition
Why it's wrong here
FTK Imager computes a hash during acquisition, not when the image is subsequently mounted for analysis. As data streams from the source drive, FTK Imager calculates MD5/SHA1 values in real time and stores them in the image metadata. Therefore, the hash is already present before any mounting occurs, making this statement incorrect.
- ✗
FTK Imager does not support hash verification; a separate tool must be used
Why it's wrong here
FTK Imager includes a native verification feature that recomputes hash values from an existing image and compares them against the embedded checksums. This built-in capability means an investigator does not need a separate tool such as HashCalc or EnCase to confirm the image's integrity. The "Verify Image" function directly validates the acquired image's hash values without requiring the original drive.
- ✗
The hash is compared to a known-good hash from the manufacturer's database
Why it's wrong here
The hash comparison is never made against a manufacturer's database; it compares the image's computed hash to the hash calculated from the original source drive during acquisition. There is no central repository of drive hashes maintained by manufacturers, and the forensic hash serves to prove the image is a bit-for-bit copy of the evidence, not to identify drive make, model, or firmware. This correct answer is about ensuring the evidentiary copy matches the seized device, not about matching some third-party reference.
- ✓
The image file includes embedded hash values that can be verified later to ensure data integrity
Why this is correct
Expert Witness Format (E01) images embed CRC32 checksums for each chunk and MD5/SHA1 hashes for the entire file, allowing later verification without access to the original drive. When the investigator re-opens the image, FTK Imager recomputes these values and compares them to the stored values to detect any alteration or corruption. Because the embedded hash values are stored inside the image file itself, they provide an independent integrity check even after the source is no longer available.
Go deeper
Related to this question
Learn chapter
Forensic Tools and Laboratory Setup
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.