200-201 · Question #500
A security specialist is investigating an incident regarding a recent major breach in the organization. The accounting data from a 24-month period is affected due to a trojan detected in a…
The correct answer is D. tampered image. In digital forensics, when an image of a system is taken for evidence, its hash value (e.g., using MD5 or SHA-256) is calculated to ensure its integrity. If the hash of a newly created image does not match the original, it indicates that the data has been altered, either…
Question
A security specialist is investigating an incident regarding a recent major breach in the organization. The accounting data from a 24-month period is affected due to a trojan detected in a department's critical server. A security analyst investigates the incident and discovers that an incident response team member who detected a trojan during regular AV scans had made an image of the server for evidence purposes. The security analyst made an image again to compare the hashes of the two images, and they appeared to differ and do not match. Which type of evidence is the security analyst dealing with?
Options
- Achecksum violated image
- Bintegrity violated image
- Cuntampered image
- Dtampered image
How the community answered
(35 responses)- A9% (3)
- B3% (1)
- C14% (5)
- D74% (26)
Explanation
In digital forensics, when an image of a system is taken for evidence, its hash value (e.g., using MD5 or SHA-256) is calculated to ensure its integrity. If the hash of a newly created image does not match the original, it indicates that the data has been altered, either intentionally or unintentionally. This suggests tampering with the evidence, which compromises its reliability in an investigation.
Topics
Community Discussion
No community discussion yet for this question.