CHFI Computer Forensics Fundamentals and Process Practice Question
Which TWO of the following are common hashing algorithms used to verify the integrity of forensic images? (Select two.)
⚠ Common exam trap
The CHFI exam often tests the distinction between encryption algorithms (AES, Blowfish, RSA) and hashing algorithms (MD5, SHA-1), trapping candidates who confuse confidentiality functions with integrity verification functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SHA-1
SHA-1 (B) is a cryptographic hash function that produces a 160-bit digest and is widely used in forensic imaging tools to verify that a disk image has not been altered, making it correct here. MD5 (E) is likewise a common hashing algorithm producing a 128-bit digest, and it is routinely paired with SHA-1 to validate the integrity of forensic images, so it is also correct. AES (A) is a symmetric block cipher used for encryption, not a hashing algorithm, so it does not verify integrity. Blowfish (C) is also a symmetric encryption cipher, not a hash function. RSA (D) is an asymmetric public-key algorithm used for encryption and digital signatures, not for generating integrity hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AES
Why it's wrong here
AES (Advanced Encryption Standard) is a symmetric block cipher used for reversible encryption, not for hashing. A hash function is a one-way, deterministic transformation that produces a fixed-size digest, whereas AES requires a secret key and can be decrypted to recover the original plaintext. In digital forensics, AES may protect data at rest or in transit, but it cannot serve to verify file integrity like a hashing algorithm. Therefore, AES is ineligible as a common hashing algorithm.
- ✓
SHA-1
Why this is correct
SHA-1 (Secure Hash Algorithm 1) is a cryptographic hash function that generates a 160-bit (20-byte) message digest from arbitrary input data. It is widely used in digital forensics to hash evidence images and files, ensuring integrity throughout the chain of custody. Although collision attacks (e.g., the SHAttered example) have weakened its suitability for digital signatures, SHA-1 is still accepted for integrity verification in many forensic workflows. Its deterministic, one-way nature makes it a proper hashing algorithm, not an encryption or signing scheme.
- ✗
Blowfish
Why it's wrong here
Blowfish is a symmetric-key block cipher introduced by Bruce Schneier in 1993, operating on 64-bit blocks with key lengths from 32 to 448 bits. It is a reversible encryption algorithm, meaning ciphertext can be decrypted back to plaintext using the same key, which is fundamentally different from hashing. Hash functions are non-invertible and produce a fixed-length fingerprint without any keyed reversal process. Thus, Blowfish cannot be classified as a hashing algorithm and is incorrect for this question.
- ✗
RSA
Why it's wrong here
RSA is an asymmetric (public-key) cryptosystem that relies on the computational difficulty of factoring large composite numbers. It is used for encryption, digital signatures, and key exchange, but it is not a hashing algorithm because it is invertible with the private key and its output size varies with the modulus length. Hash functions are non-invertible, deterministic, and output a fixed-size digest regardless of any key. In forensic practice, RSA would be used for authentication or confidentiality, not for generating integrity hashes of evidence.
- ✓
MD5
Why this is correct
MD5 (Message Digest Algorithm 5) is a cryptographic hash function that produces a 128-bit (16-byte) digest and has been historically common in forensic tools and integrity checks. Despite known collision vulnerabilities that make it unsuitable for adversarial contexts like digital signatures, MD5 is still used for non-adversarial integrity verification and as an identifier in hash databases such as the NIST NSRL. Its one-way, deterministic output characterizes it as a genuine hashing algorithm, and it remains common in practice even if not recommended for high-security applications. Therefore, MD5 is a correct option for a common hashing algorithm.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.