Courseiva

CHFI Computer Forensics Fundamentals and Process Practice Question

Which TWO of the following are common hashing algorithms used to verify the integrity of forensic images? (Select two.)

⚠ Common exam trap

The CHFI exam often tests the distinction between encryption algorithms (AES, Blowfish, RSA) and hashing algorithms (MD5, SHA-1), trapping candidates who confuse confidentiality functions with integrity verification functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SHA-1

SHA-1 (B) is a cryptographic hash function that produces a 160-bit digest and is widely used in forensic imaging tools to verify that a disk image has not been altered, making it correct here. MD5 (E) is likewise a common hashing algorithm producing a 128-bit digest, and it is routinely paired with SHA-1 to validate the integrity of forensic images, so it is also correct. AES (A) is a symmetric block cipher used for encryption, not a hashing algorithm, so it does not verify integrity. Blowfish (C) is also a symmetric encryption cipher, not a hash function. RSA (D) is an asymmetric public-key algorithm used for encryption and digital signatures, not for generating integrity hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AES

    Why it's wrong here

    AES (Advanced Encryption Standard) is a symmetric block cipher used for reversible encryption, not for hashing. A hash function is a one-way, deterministic transformation that produces a fixed-size digest, whereas AES requires a secret key and can be decrypted to recover the original plaintext. In digital forensics, AES may protect data at rest or in transit, but it cannot serve to verify file integrity like a hashing algorithm. Therefore, AES is ineligible as a common hashing algorithm.

  • ✓

    SHA-1

    Why this is correct

    SHA-1 (Secure Hash Algorithm 1) is a cryptographic hash function that generates a 160-bit (20-byte) message digest from arbitrary input data. It is widely used in digital forensics to hash evidence images and files, ensuring integrity throughout the chain of custody. Although collision attacks (e.g., the SHAttered example) have weakened its suitability for digital signatures, SHA-1 is still accepted for integrity verification in many forensic workflows. Its deterministic, one-way nature makes it a proper hashing algorithm, not an encryption or signing scheme.

  • ✗

    Blowfish

    Why it's wrong here

    Blowfish is a symmetric-key block cipher introduced by Bruce Schneier in 1993, operating on 64-bit blocks with key lengths from 32 to 448 bits. It is a reversible encryption algorithm, meaning ciphertext can be decrypted back to plaintext using the same key, which is fundamentally different from hashing. Hash functions are non-invertible and produce a fixed-length fingerprint without any keyed reversal process. Thus, Blowfish cannot be classified as a hashing algorithm and is incorrect for this question.

  • ✗

    RSA

    Why it's wrong here

    RSA is an asymmetric (public-key) cryptosystem that relies on the computational difficulty of factoring large composite numbers. It is used for encryption, digital signatures, and key exchange, but it is not a hashing algorithm because it is invertible with the private key and its output size varies with the modulus length. Hash functions are non-invertible, deterministic, and output a fixed-size digest regardless of any key. In forensic practice, RSA would be used for authentication or confidentiality, not for generating integrity hashes of evidence.

  • ✓

    MD5

    Why this is correct

    MD5 (Message Digest Algorithm 5) is a cryptographic hash function that produces a 128-bit (16-byte) digest and has been historically common in forensic tools and integrity checks. Despite known collision vulnerabilities that make it unsuitable for adversarial contexts like digital signatures, MD5 is still used for non-adversarial integrity verification and as an identifier in hash databases such as the NIST NSRL. Its one-way, deterministic output characterizes it as a genuine hashing algorithm, and it remains common in practice even if not recommended for high-security applications. Therefore, MD5 is a correct option for a common hashing algorithm.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.