CompTIA Security+ (SY0-701)Security OperationsMedium

A security analyst is conducting a forensic investigation after a suspected intrusion. To ensure the integrity and authenticity of the acquired evidence, the analyst calculates a cryptographic hash of the suspect's hard drive before and after creating a forensic image. What is the PRIMARY purpose of this action?

  1. ATo recover deleted files from the drive.
  2. BTo verify that the image is an exact, unaltered copy of the original.
  3. CTo decrypt encrypted data on the drive.
  4. DTo identify the type of file system used on the drive.
Show answer & explanation

Correct answer: B. To verify that the image is an exact, unaltered copy of the original.

Calculating a cryptographic hash (like MD5 or SHA256) of a drive before and after imaging is a crucial step in digital forensics. If the hashes match, it provides mathematical proof that the forensic image is an exact, bit-for-bit copy of the original evidence and has not been tampered with during the acquisition process.

Why the other options are wrong

  • A. Hashing does not recover deleted files; specialized data recovery tools are used for that purpose.
  • C. Hashing does not decrypt data; it generates a fixed-size string representing the data's integrity.
  • D. Hashing does not identify file system types; other forensic tools are used for that purpose.

Data Integrity (Digital Forensics)

Ensuring that digital evidence remains complete and unaltered from the moment it is collected until it is presented in court, typically verified using cryptographic hashing.

  • Crucial for admissibility of evidence.
  • Verifies evidence hasn't been tampered with.
  • Cryptographic hashes (MD5, SHA256) are commonly used.

Memory trick: To be 'Sure' the data is 'Pure', hash it 'Before' and 'After' for 'Integrity'.

More Security Operations questions