Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

During a forensic investigation, an analyst creates a forensic image using `dcfldd` with the command: `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=10M`. What is the purpose of the `hashwindow` parameter?

⚠ Common exam trap

EC-Council often tests the distinction between parameters that set the hash algorithm (`hash=`) versus those that control hash granularity (`hashwindow`), leading candidates to confuse `hashwindow` with limiting the total data or enabling error correction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It creates a hash for every 10 MB block of data

The `hashwindow` parameter in `dcfldd` specifies the size of the data chunks for which individual hash values are computed. With `hashwindow=10M`, the tool generates a SHA-256 hash for every 10 MB block of the input data, allowing verification of integrity on a per-block basis rather than only a single hash for the entire image. This is useful for detecting corruption or tampering in specific segments of large forensic images.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It limits the total amount of data to hash to 10 MB

    Why it's wrong here

    The `hashwindow=10M` setting in dcfldd does not impose a 10 MB cap on the amount of data being hashed; rather, it partitions the input stream into 10-megabyte segments and computes a separate hash for each segment. The entire device or image file is still read and hashed in its entirety—the window only controls the 'grain size' of the individual hash computations. Confusing a partitioning granularity with a data limit is a common misinterpretation of this option.

  • ✓

    It creates a hash for every 10 MB block of data

    Why this is correct

    With `hashwindow=10M`, dcfldd computes an independent hash value for every 10 MB block of input, allowing the analyst to verify each segment individually rather than relying solely on a single whole-file digest. This block-wise hashing is crucial for large forensic images because it pinpoints exactly which 10 MB region has changed or become corrupted, enabling targeted re-acquisition or analysis. It does not alter the total data processed, and the root hash over the entire stream may still be generated simultaneously if requested.

  • ✗

    It sets the hash algorithm to SHA-256

    Why it's wrong here

    The `hashwindow` option only controls the frequency or block size at which hash values are emitted; it has no effect on which hash algorithm is selected. The algorithm is explicitly chosen by the separate `hash=sha256` parameter (or `md5`, `sha1`, etc.), while `hashwindow` merely states that a new digest should be calculated every 10 MB of input. Because SHA-256 is a cryptographic function with a fixed 256-bit output, it is not something that a windowing parameter could 'set'—the two options address different aspects of the hashing operation.

  • ✗

    It enables error correction for every 10 MB

    Why it's wrong here

    dcfldd's hashing capabilities—including per-window hashes—are purely for detecting corruption or unauthorized modification, not for repairing it. Error correction would require storing redundant information, such as Reed-Solomon parity bytes, and dcfldd does not generate or use such redundancy during acquisition. If a 10 MB segment fails its hash check, the analyst learns precisely which part is suspect but cannot reconstruct the original data from the hash alone, so 'enabling error correction' is not a valid interpretation of this option.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.