CompTIA Security+ (SY0-701)Security OperationsMedium

A security analyst is conducting a forensic investigation after a suspected intrusion. To preserve the integrity of the collected evidence, the analyst calculates a cryptographic hash of a seized hard drive image before and after analysis. Which principle of digital forensics does this action primarily support?

  1. ANon-repudiation
  2. BLocard's Exchange Principle
  3. CChain of custody
  4. DData integrity
Show answer & explanation

Correct answer: D. Data integrity

Calculating a cryptographic hash of evidence before and after analysis is done to verify that the evidence has not been altered or corrupted. This directly ensures the 'data integrity' of the forensic artifact, proving it remains in its original state.

Why the other options are wrong

  • A. Non-repudiation ensures a party cannot deny an action, typically related to digital signatures or logs, not the state of an image.
  • B. Locard's Exchange Principle states that every contact leaves a trace, which is about evidence creation, not preservation.
  • C. Chain of custody tracks the handling and transfer of evidence, not its internal consistency.

Data Integrity (Digital Forensics)

The principle that digital evidence must remain complete, accurate, and unaltered from the moment of collection through analysis and presentation.

  • Crucial for admissibility of evidence in legal proceedings.
  • Verified using cryptographic hashing (e.g., MD5, SHA-256).
  • Any change to the data will result in a different hash value.

Memory trick: Hashing ensures data 'Integrity' – it's Intact!

More Security Operations questions