Courseiva

Common Hashing Algorithms in Forensic Imaging

Which TWO of the following hashing algorithms are commonly used to verify the integrity of forensic images? (Choose two.)

Quick Answer

The answer is SHA-1 and MD5, the two hashing algorithms most commonly used to verify the integrity of forensic images. These algorithms produce fixed-size hash values—160-bit for SHA-1 and 128-bit for MD5—that serve as unique digital fingerprints; if the hash of the original image matches the hash of a copy, the data is considered unaltered. On the Computer Hacking Forensic Investigator CHFI exam, this concept tests your understanding of evidence integrity verification, often appearing in questions about tools like FTK Imager or EnCase. A common trap is assuming SHA-256 or newer algorithms are preferred in practice, but forensic workflows still rely on SHA-1 and MD5 due to their speed and widespread tool support, despite known collision weaknesses. Memory tip: think "5 and 5"—SHA-1 (160 bits) and MD5 (128 bits) are the forensic standard pair, like a digital handshake for evidence.

⚠ Common exam trap

EC-Council often tests the distinction between hashing algorithms (integrity) and encryption algorithms (confidentiality), so the trap here is that candidates confuse RSA and AES as hashing algorithms because they are cryptographic primitives, but they serve entirely different purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SHA-1

SHA-1 and MD5 are the two hashing algorithms most commonly used in forensic practice to verify the integrity of forensic images. They produce a fixed-size hash value (160-bit for SHA-1, 128-bit for MD5) that acts as a digital fingerprint; if the hash of the original image matches the hash of a copy, the data is considered unchanged. Despite known collision weaknesses, they remain the de facto standards in tools like FTK Imager, EnCase, and dd due to their speed and widespread tool support.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SHA-3

    Why it's wrong here

    SHA-3 is a cryptographic hash function and does verify forensic image integrity, so it does not fail this scenario. It is tempting to reject only because SHA-2 and MD5 appear in older tooling, yet SHA-3 belongs to the same hash family and is a valid answer.

  • ✓

    SHA-1

    Why this is correct

    SHA-1 generates a 160-bit digest and is widely accepted for validating forensic image integrity, often recorded alongside MD5. It satisfies the stem's requirement by providing a second, independent hash to demonstrate that acquired evidence remains unchanged.

  • ✗

    RSA

    Why it's wrong here

    RSA is an asymmetric public-key cryptosystem used for encryption and digital signatures, not a hashing algorithm, so it cannot generate the digest compared to verify image integrity. It is tempting because RSA signatures often accompany evidence, but signing relies on a separate hash underneath.

  • ✗

    AES

    Why it's wrong here

    AES is a symmetric block cipher for encryption, not a hash function, so it cannot produce the fixed-length digest used to verify forensic image integrity. It is tempting because AES appears throughout forensic tooling for encrypting evidence containers, which is a separate task from integrity verification.

  • ✓

    MD5

    Why this is correct

    MD5 produces a 128-bit digest and is a standard forensic integrity check, letting investigators confirm a disk image has not altered since acquisition. Its speed suits hashing large evidence files, satisfying the stem's requirement for a commonly used image-verification algorithm.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are common hashing algorithms used to verify the integrity of forensic images? (Select two.)

easy
  • A.AES
  • ✓ B.SHA-1
  • C.Blowfish
  • D.RSA
  • ✓ E.MD5

Why B: SHA-1 (B) is a cryptographic hash function that produces a 160-bit digest and is widely used in forensic imaging tools to verify that a disk image has not been altered, making it correct here. MD5 (E) is likewise a common hashing algorithm producing a 128-bit digest, and it is routinely paired with SHA-1 to validate the integrity of forensic images, so it is also correct. AES (A) is a symmetric block cipher used for encryption, not a hashing algorithm, so it does not verify integrity. Blowfish (C) is also a symmetric encryption cipher, not a hash function. RSA (D) is an asymmetric public-key algorithm used for encryption and digital signatures, not for generating integrity hashes.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.