Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

An analyst performs forensic imaging using the command: dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt bs=4096 conv=noerror,sync. What is the PRIMARY purpose of the 'hash=sha256' and 'hashlog=hash.txt' parameters?

⚠ Common exam trap

EC-Council often tests the distinction between hashing (integrity) and encryption (confidentiality), so the trap here is that candidates confuse the purpose of a hash algorithm with that of an encryption cipher, leading them to incorrectly select Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To ensure the image is an exact bit-for-bit copy and provide an integrity check.

The `hash=sha256` parameter instructs dcfldd to compute a SHA-256 hash of the input data as it is read, and `hashlog=hash.txt` writes that hash value to a separate file. This allows the analyst to later verify that the forensic image (`image.dd`) is an exact bit-for-bit copy of the source (`/dev/sda`) by recomputing the hash and comparing it to the stored value, ensuring data integrity and admissibility in court.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To encrypt the image file to prevent unauthorized access.

    Why it's wrong here

    Hashing is a one-way mathematical function that produces a fixed-size digest, not an encryption cipher. Hashing does not use a key and cannot be reversed to recover original data, whereas encryption is reversible with a key. Therefore, dcfldd's hash options provide integrity verification, not confidentiality or access control.

  • ✗

    To compress the image to save disk space.

    Why it's wrong here

    Cryptographic hashing does not alter the size of the acquired image; the hash output is a short, fixed-length value regardless of the input size, and dcfldd does not compress data by default. Compression aims to reduce disk usage, while hashing verifies data authenticity. Thus, the hash option cannot be used to save storage space.

  • ✓

    To ensure the image is an exact bit-for-bit copy and provide an integrity check.

    Why this is correct

    The hash option in dcfldd calculates a cryptographic digest of every bit read from the source device, creating a unique digital fingerprint of the acquired data. Hashing ensures that the resulting image is a bit-for-bit copy and allows the examiner to later run the same algorithm to confirm the image has not been modified, which is essential for maintaining evidence integrity in legal proceedings.

  • ✗

    To split the image into smaller chunks for easier transport.

    Why it's wrong here

    dcfldd does have a separate 'split=' parameter that breaks the output into multi-part files for easier transport, but hashing and splitting are distinct features. The hash functions compute integrity digests; they do not divide the image into chunks. Consequently, hashing is unrelated to file size management or media portability.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.