Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

An investigator creates a forensic image using dcfldd with the following command: dcfldd if=/dev/sdb of=image.dd hash=sha256 hashwindow=10M hashlog=hash.txt. What is the effect of the 'hashwindow=10M' parameter?

⚠ Common exam trap

The CHFI exam often tests the distinction between 'hashing during acquisition' and 'hashing after completion' — the trap here is that candidates may assume `hashwindow` is for performance tuning (buffer size) or for pre-copy verification, rather than understanding it as a segmentation feature for incremental hashing and logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It divides the output into 10 MB chunks and hashes each chunk, logging the results

The `hashwindow=10M` parameter in dcfldd instructs the tool to compute a SHA-256 hash for every 10 MB segment (window) of the input data as it is being copied, and then log each segment's hash to the specified hashlog file. This allows the investigator to verify the integrity of individual chunks of the forensic image, which is useful for detecting corruption or tampering in specific regions of the image without rehashing the entire file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It divides the output into 10 MB chunks and hashes each chunk, logging the results

    Why this is correct

    The hashwindow parameter in dcfldd instructs the tool to compute a cryptographic hash (e.g., MD5 or SHA-256) for every 10 MiB segment of the data stream as it copies, logging each segment's hash to a designated hash log. This piecewise hashing enables examiners to verify specific portions of an acquired image independently rather than relying solely on a single hash for the entire output, which is especially critical for very large forensic images. It is specified alongside hash= and hashlog= options to produce a record of per-window hashes during acquisition.

  • ✗

    It sets the input buffer size to 10 MB for performance

    Why it's wrong here

    This misinterprets hashwindow as a performance-related I/O buffer setting. In dcfldd, the size of the read/write buffer is governed by the bs (block size) and count parameters, which dictate the number of bytes processed per system call, not by hashwindow. hashwindow only determines the granularity at which the running hash is calculated and recorded; it has no effect on the amount of memory used for buffering or the speed of the copy operation itself.

  • ✗

    It verifies the hash of the input device in 10 MB windows before copying

    Why it's wrong here

    hashwindow does not cause any pre-copy verification of the source device. Rather, dcfldd computes hashes of data as it is read and written, operating on the output stream, not as a preliminary integrity check. The tool may offer a separate verify or match feature, but that is not what hashwindow does; it simply partitions the hashing process into chunks during the single pass, and there is no separate verification pass before copying begins.

  • ✗

    It causes the tool to hash the entire image only after completion

    Why it's wrong here

    This is incorrect because hashwindow generates per-block hashes continuously during the acquisition, not just an overall hash after completion. While dcfldd does compute a final hash for the entire image as well, the hashwindow option ensures that individual 10 MiB segments are hashed and logged in real time as they are written to the output. Thus, the examiner receives immediate piecewise integrity data rather than waiting for the whole copy to finish before any hash is produced.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.