Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

Which hashing algorithm is commonly used in forensic imaging to verify the integrity of evidence and is considered more secure than MD5?

⚠ Common exam trap

EC-Council often tests the misconception that SHA-1 is still acceptable for forensic integrity checks because it was once the standard, but the trap is that SHA-1 is now deprecated due to practical collision attacks, while SHA-256 is the current recommended minimum.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SHA-256

SHA-256 is the correct answer because it is a widely adopted cryptographic hash function in forensic imaging tools (e.g., FTK Imager, EnCase) to verify evidence integrity. It produces a 256-bit (32-byte) hash value and is considered collision-resistant, making it significantly more secure than MD5, which has known collision vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SHA-256

    Why this is correct

    SHA-256, a member of the SHA-2 family, produces a 256-bit digest and is currently considered cryptographically secure for integrity verification. In forensic imaging, it is the de facto standard because it is collision-resistant and preimage-resistant, meaning it is computationally infeasible to find two different data sets with the same hash or to reconstruct original data from the digest. Tools such as EnCase, FTK, and dd with sha256sum use it to validate that a forensic image is a perfect bit-for-bit copy of the original medium.

  • ✗

    SHA-1

    Why it's wrong here

    SHA-1 generates a 160-bit hash and was widely used in forensic tools, but it now has demonstrated collision attacks, notably the SHAttered attack where two distinct PDFs share the same digest. Because the National Institute of Standards and Technology (NIST) has deprecated SHA-1 for cryptographic use, relying on it in forensic imaging risks allowing an attacker to manipulate evidence while preserving the hash value. Consequently, professional forensic practices have moved to SHA-256 for tamper-evident integrity checks, with SHA-1 only appearing in legacy artifacts.

  • ✗

    CRC32

    Why it's wrong here

    CRC32 is a 32-bit cyclic redundancy check used primarily for detecting accidental errors in data transmission or storage, not for detecting intentional tampering. It is not a cryptographic hash function because it lacks key properties such as preimage resistance, and it is trivial to craft an alternate data block that yields the same CRC32 checksum. In forensic imaging, CRC32 can verify that a copy matches a source under benign conditions, but it offers no protection against an adversary who can deliberately modify evidence while recalculating the checksum, so it is unsuitable for evidentiary integrity.

  • ✗

    MD5

    Why it's wrong here

    MD5 computes a 128-bit message digest and was popularized in forensic tools for its speed and simple implementation, but it now has well-known practical collision attacks, including chosen-prefix collisions that allow an attacker to create two files with identical MD5 hashes. Such collisions undermine the fundamental evidentiary guarantee that a hash uniquely identifies the original data, because a maliciously substituted file could match the recorded hash. Thus, while MD5 may still be found in legacy forensic workflows or for non-security checks, it is no longer acceptable for court-admissible forensic integrity verification.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.