Security OperationsCâu 71 / 100
During forensic acquisition, why is a cryptographic hash taken of a disk image?
a.To prove the copy was not altered
b.To compress the image
c.To encrypt the evidence
d.To speed up analysis
Giải thích
Hashing the original and the forensic image proves they are identical and that the evidence was not modified. Matching hashes demonstrate integrity throughout the investigation. Any change to the data would produce a different hash.
Luyện miễn phí toàn bộ 100 câu hỏi — không cần đăng ký.
Câu hỏi liên quan cùng chủ đề
- Which process applies vendor updates to fix known software vulnerabilities?
- Reducing a system's attack surface by disabling unneeded services and applying secure configurations is called:
- Which practice ensures evidence remains admissible by documenting who handled it and when?
- Which type of backup captures only the data changed since the last full backup and does not clear the archive bit each time?
- Which metric defines the maximum acceptable amount of data loss measured in time?
- Which metric defines the maximum acceptable time to restore a service after an outage?
Cập nhật gần nhất: · quy trình kiểm tra
Đội Ngũ Biên Tập PrepPass · Đối chiếu với CompTIA Security+ (SY0-701) · Quy trình kiểm tra