CHFI Computer Forensics Fundamentals and Process Practice Question
Which hashing algorithm is commonly used in forensic imaging to verify the integrity of evidence and is considered more secure than MD5?
⚠ Common exam trap
EC-Council often tests the misconception that SHA-1 is still acceptable for forensic integrity checks because it was once the standard, but the trap is that SHA-1 is now deprecated due to practical collision attacks, while SHA-256 is the current recommended minimum.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SHA-256
SHA-256 is the correct answer because it is a widely adopted cryptographic hash function in forensic imaging tools (e.g., FTK Imager, EnCase) to verify evidence integrity. It produces a 256-bit (32-byte) hash value and is considered collision-resistant, making it significantly more secure than MD5, which has known collision vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SHA-256
Why this is correct
SHA-256, a member of the SHA-2 family, produces a 256-bit digest and is currently considered cryptographically secure for integrity verification. In forensic imaging, it is the de facto standard because it is collision-resistant and preimage-resistant, meaning it is computationally infeasible to find two different data sets with the same hash or to reconstruct original data from the digest. Tools such as EnCase, FTK, and dd with sha256sum use it to validate that a forensic image is a perfect bit-for-bit copy of the original medium.
- ✗
SHA-1
Why it's wrong here
SHA-1 generates a 160-bit hash and was widely used in forensic tools, but it now has demonstrated collision attacks, notably the SHAttered attack where two distinct PDFs share the same digest. Because the National Institute of Standards and Technology (NIST) has deprecated SHA-1 for cryptographic use, relying on it in forensic imaging risks allowing an attacker to manipulate evidence while preserving the hash value. Consequently, professional forensic practices have moved to SHA-256 for tamper-evident integrity checks, with SHA-1 only appearing in legacy artifacts.
- ✗
CRC32
Why it's wrong here
CRC32 is a 32-bit cyclic redundancy check used primarily for detecting accidental errors in data transmission or storage, not for detecting intentional tampering. It is not a cryptographic hash function because it lacks key properties such as preimage resistance, and it is trivial to craft an alternate data block that yields the same CRC32 checksum. In forensic imaging, CRC32 can verify that a copy matches a source under benign conditions, but it offers no protection against an adversary who can deliberately modify evidence while recalculating the checksum, so it is unsuitable for evidentiary integrity.
- ✗
MD5
Why it's wrong here
MD5 computes a 128-bit message digest and was popularized in forensic tools for its speed and simple implementation, but it now has well-known practical collision attacks, including chosen-prefix collisions that allow an attacker to create two files with identical MD5 hashes. Such collisions undermine the fundamental evidentiary guarantee that a hash uniquely identifies the original data, because a maliciously substituted file could match the recorded hash. Thus, while MD5 may still be found in legacy forensic workflows or for non-security checks, it is no longer acceptable for court-admissible forensic integrity verification.
Go deeper
Related to this question
Learn chapter
Forensic Tools and Laboratory Setup
Key term
Disk Imaging
Disk imaging is the process of creating an exact, bit-for-bit copy of a storage drive, preserving all data, deleted files, and unallocated space for forensic analysis or system recovery.
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.