Skip to content

CS Professional · Internal and Forensic Audit · Cyber Forensics

A forensic examiner at a Mumbai company finds that the hash value of the working image of a server disk differs from the hash recorded at acquisition. What is the most appropriate conclusion?

The integrity of the image is in doubt. A hash mismatch shows the data has changed since acquisition, so the image should not be relied on until it is re-acquired from the original or the difference is explained. Equal file size does not prove identical content.

  1. AThe image is still reliable because file sizes are the same
  2. BThe image's integrity is in doubt and it should not be relied upon until re-acquired or the discrepancy is explainedCorrect
  3. CThe hash difference is normal when a different tool opens the image
  4. DThe original disk must be formatted and the copy treated as the master

Explanation

A hash function produces a different value if even one bit changes. A mismatch shows the image is not identical to what was acquired, so integrity cannot be demonstrated. The examiner should investigate and re-image from the original if needed. Same file size proves nothing about content.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Forensics shows your real accuracy, how long you take and where you lose marks.

More Cyber Forensics questions