CompTIA Security+ (SY0-701)Security OperationsHard

A digital forensics examiner creates a bit-for-bit image of a seized hard drive and calculates a SHA-256 hash of both the original and the image. What is the PRIMARY purpose of this hashing step in maintaining chain of custody?

  1. ATo compress the image file for easier storage and transport
  2. BTo encrypt the evidence so unauthorized parties cannot view it
  3. CTo speed up the indexing process during keyword searches
  4. DTo prove the forensic image is an exact, unaltered copy of the original evidence
Show answer & explanation

Correct answer: D. To prove the forensic image is an exact, unaltered copy of the original evidence

Hashing the original drive and its forensic image produces a unique digital fingerprint; matching hash values prove the copy is identical and unaltered, which is essential for maintaining evidence integrity and admissibility in legal proceedings as part of chain of custody.

Why the other options are wrong

  • A. Hashing does not compress data; it generates a fixed-size checksum regardless of file size.
  • B. Hashing does not encrypt data; it produces a fixed-length digest for integrity verification.
  • C. Hashing is unrelated to search indexing speed.

Hashing for Evidence Integrity

Cryptographic hashing (e.g., SHA-256) creates a unique digest of forensic evidence used to verify that a copy is identical to the original and has not been altered.

  • Matching hash values confirm image integrity
  • Part of maintaining chain of custody documentation
  • Common algorithms: SHA-256, MD5 (legacy)
  • Any evidence alteration changes the hash completely

Memory trick: Same hash, same evidence—no tampering.

More Security Operations questions