Which TWO of the following hashing algorithms are commonly used to verify the integrity of forensic images? (Choose two.)
SHA-1 generates a 160-bit digest and is widely accepted for validating forensic image integrity, often recorded alongside MD5. It satisfies the stem's requirement by providing a second, independent hash to demonstrate that acquired evidence remains unchanged.
Why this answer
SHA-1 and MD5 are the two hashing algorithms most commonly used in forensic practice to verify the integrity of forensic images. They produce a fixed-size hash value (160-bit for SHA-1, 128-bit for MD5) that acts as a digital fingerprint; if the hash of the original image matches the hash of a copy, the data is considered unchanged. Despite known collision weaknesses, they remain the de facto standards in tools like FTK Imager, EnCase, and dd due to their speed and widespread tool support.
Exam trap
EC-Council often tests the distinction between hashing algorithms (integrity) and encryption algorithms (confidentiality), so the trap here is that candidates confuse RSA and AES as hashing algorithms because they are cryptographic primitives, but they serve entirely different purposes.