nerdexam
EC-Council

312-49 · Question #12

Which of the following is not a part of disk imaging tool requirements?

The correct answer is D. The tool should not compute a hash value for the complete bit stream copy generated from an. Reputable forensic disk imaging tools are required to compute a cryptographic hash (e.g., MD5 or SHA-1) of the complete bit-stream copy to verify integrity and prove the image has not been altered. Option D states the tool 'should NOT compute a hash value,' which is the opposite

Submitted by ngozi_ng· Apr 18, 2026Disk Forensics

Question

Which of the following is not a part of disk imaging tool requirements?

Options

  • AThe tool should not change the original content
  • BThe tool should log I/O errors in an accessible and readable form, including the type and location
  • CThe tool must have the ability to be held up to scientific and peer review
  • DThe tool should not compute a hash value for the complete bit stream copy generated from an

How the community answered

(29 responses)
  • A
    3% (1)
  • C
    7% (2)
  • D
    90% (26)

Explanation

Reputable forensic disk imaging tools are required to compute a cryptographic hash (e.g., MD5 or SHA-1) of the complete bit-stream copy to verify integrity and prove the image has not been altered. Option D states the tool 'should NOT compute a hash value,' which is the opposite of a valid requirement - making it the correct choice as 'not a part' of proper imaging tool requirements. Options A (not altering original content), B (logging I/O errors), and C (withstanding peer/scientific review) are all legitimate, accepted requirements for forensic imaging tools.

Topics

#Disk imaging#Forensic tools#Data integrity#Hashing

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice