Courseiva

CHFI Mobile and Malware Forensics Practice Question

An analyst extracts an iTunes backup from a Windows computer. The backup contains a file manifest.plist with cryptographic hashes. What is the primary purpose of these hashes in the backup process?

⚠ Common exam trap

EC-Council often tests the distinction between integrity verification (hashing) and confidentiality (encryption), so candidates may confuse the purpose of hashes with encryption or compression.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To verify the integrity of the backup files

The cryptographic hashes in an iTunes backup's manifest.plist file are used to verify the integrity of the backup files. Each hash corresponds to a file in the backup, allowing the system to detect any corruption or tampering by comparing the stored hash against a newly computed hash of the file data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To compress the backup data

    Why it's wrong here

    Hashing the backup files does not reduce their size. Compression is a separate process that typically uses algorithms such as DEFLATE or LZMA to remove redundant data. A hash, by contrast, is a fixed-length digest computed from the file's contents; it adds no compression benefit and actually requires storing the hash value separately, slightly increasing the total data footprint.

  • ✓

    To verify the integrity of the backup files

    Why this is correct

    Computing a cryptographic hash (e.g., SHA-1 or MD5) of each backup file and comparing it against a known-good value confirms that the file's contents have not been modified, corrupted, or tampered with since the hash was created. This is the standard integrity-checking mechanism: any single-bit change in the file produces a completely different hash, allowing the analyst to detect accidental corruption or intentional alteration. In forensic examinations, verifying hashes ensures the extracted backup is an exact, trustworthy copy of the original evidence.

  • ✗

    To index the backup for faster searching

    Why it's wrong here

    Indexing is a separate operation that builds a searchable structure (like a B-tree or inverted index) to speed up queries. A hash is not an index; it does not organize data by content or filename, nor does it allow partial or range searches. While a hash can be used in a hash table for quick lookups, that is not the purpose here—the analyst is not building a search index for the backup's contents.

  • ✗

    To encrypt the backup files

    Why it's wrong here

    Encryption is a reversible transformation that scrambles data using a cipher and a secret key to provide confidentiality. A hash is a one-way, irreversible digest; it cannot be used to recover the original data and therefore cannot encrypt anything. Hashing and encryption serve fundamentally different goals: hashing ensures integrity and authenticity, while encryption ensures secrecy. Using a hash would not protect the backup's contents from being read.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.