Security Operations第 71 / 100 题
During forensic acquisition, why is a cryptographic hash taken of a disk image?
a.To prove the copy was not altered
b.To compress the image
c.To encrypt the evidence
d.To speed up analysis
解析
Hashing the original and the forensic image proves they are identical and that the evidence was not modified. Matching hashes demonstrate integrity throughout the investigation. Any change to the data would produce a different hash.
免费刷完整 100 道题库 — 无需注册。
同考点相关题目
- Which process applies vendor updates to fix known software vulnerabilities?
- Reducing a system's attack surface by disabling unneeded services and applying secure configurations is called:
- Which practice ensures evidence remains admissible by documenting who handled it and when?
- Which type of backup captures only the data changed since the last full backup and does not clear the archive bit each time?
- Which metric defines the maximum acceptable amount of data loss measured in time?
- Which metric defines the maximum acceptable time to restore a service after an outage?