Courseiva

CHFI Evidence Acquisition and Duplication Practice Question

Exhibit

Refer to the exhibit.

Forensic Acquisition Log:

Source: /dev/sdb
Image: /mnt/evidence/case001.dd
Hash (MD5): Source= a1b2c3d4e5f6... Image= a1b2c3d4e5f6...
Hash (SHA1): Source= 1234567890ab... Image= 1234567890ab...

Verification: Passed

Based on the acquisition log, what can be concluded about the integrity of the acquired image?

⚠ Common exam trap

EC-Council often tests the misconception that a passed verification indicates the image is not forensically sound, or that using only one hash algorithm implies corruption, when in fact a matching hash confirms integrity regardless of the number of algorithms used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The image is an exact copy of the source

The acquisition log shows that the hash values computed for the source drive and the acquired image match exactly. A matching hash (e.g., MD5 or SHA-1) verifies that the image is a bit-for-bit identical copy of the original evidence, confirming forensic soundness. Therefore, the image is an exact copy of the source, making option D correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The image is not forensically sound because the verification passed

    Why it's wrong here

    The claim reverses cause and effect: verification is the procedural step that confirms the acquired image's hash values match the source's known hashes. Far from making the image unsound, a passing verification is the primary evidence of forensic integrity, certifying that the image has not been altered during acquisition or storage.

  • ✗

    The source and image have different data

    Why it's wrong here

    If the source and image had different data, their cryptographic hash digests would differ; a single differing bit would produce a radically different hash. Since the acquisition log shows the hash values for the source and image are identical, the data must be byte-for-byte the same, so this conclusion is factually contradicted by the evidence.

  • ✗

    The image is corrupted because only one hash algorithm was used

    Why it's wrong here

    The log actually records two hash algorithms (typically MD5 and SHA1), and both produce matching values between source and image. Corruption would manifest as a hash mismatch, not as a consequence of the number of algorithms used; matching digests from multiple algorithms actually strengthen, rather than weaken, confidence in the image's integrity.

  • ✓

    The image is an exact copy of the source

    Why this is correct

    The acquisition log documents that the hash of the source and the hash of the acquired image are identical, and the subsequent verification step confirms these values still match. Identical hash digests plus a verified match provide strong cryptographic proof that the image is a precise, bit-for-bit duplicate of the source, which is the definition of a forensically sound copy.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.