nerdexam
Cisco

200-201 · Question #500

A security specialist is investigating an incident regarding a recent major breach in the organization. The accounting data from a 24-month period is affected due to a trojan detected in a…

The correct answer is D. tampered image. In digital forensics, when an image of a system is taken for evidence, its hash value (e.g., using MD5 or SHA-256) is calculated to ensure its integrity. If the hash of a newly created image does not match the original, it indicates that the data has been altered, either…

Submitted by khalil_dz· Mar 6, 2026Host-Based Analysis

Question

A security specialist is investigating an incident regarding a recent major breach in the organization. The accounting data from a 24-month period is affected due to a trojan detected in a department's critical server. A security analyst investigates the incident and discovers that an incident response team member who detected a trojan during regular AV scans had made an image of the server for evidence purposes. The security analyst made an image again to compare the hashes of the two images, and they appeared to differ and do not match. Which type of evidence is the security analyst dealing with?

Options

  • Achecksum violated image
  • Bintegrity violated image
  • Cuntampered image
  • Dtampered image

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    14% (5)
  • D
    74% (26)

Explanation

In digital forensics, when an image of a system is taken for evidence, its hash value (e.g., using MD5 or SHA-256) is calculated to ensure its integrity. If the hash of a newly created image does not match the original, it indicates that the data has been altered, either intentionally or unintentionally. This suggests tampering with the evidence, which compromises its reliability in an investigation.

Topics

#forensic evidence#data integrity#hashing#incident response

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice