Security OperationsQuestion 71 of 100
During forensic acquisition, why is a cryptographic hash taken of a disk image?
a.To prove the copy was not altered
b.To compress the image
c.To encrypt the evidence
d.To speed up analysis
Explanation
Hashing the original and the forensic image proves they are identical and that the evidence was not modified. Matching hashes demonstrate integrity throughout the investigation. Any change to the data would produce a different hash.
Practice all 100 questions free — no signup required.
Related questions on this topic
- Which process applies vendor updates to fix known software vulnerabilities?
- Reducing a system's attack surface by disabling unneeded services and applying secure configurations is called:
- Which practice ensures evidence remains admissible by documenting who handled it and when?
- Which type of backup captures only the data changed since the last full backup and does not clear the archive bit each time?
- Which metric defines the maximum acceptable amount of data loss measured in time?
- Which metric defines the maximum acceptable time to restore a service after an outage?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against CompTIA Security+ (SY0-701) · How we review