312-49 · Question #12
Which of the following is not a part of disk imaging tool requirements?
The correct answer is D. The tool should not compute a hash value for the complete bit stream copy generated from an. Reputable forensic disk imaging tools are required to compute a cryptographic hash (e.g., MD5 or SHA-1) of the complete bit-stream copy to verify integrity and prove the image has not been altered. Option D states the tool 'should NOT compute a hash value,' which is the opposite
Question
Which of the following is not a part of disk imaging tool requirements?
Options
- AThe tool should not change the original content
- BThe tool should log I/O errors in an accessible and readable form, including the type and location
- CThe tool must have the ability to be held up to scientific and peer review
- DThe tool should not compute a hash value for the complete bit stream copy generated from an
How the community answered
(29 responses)- A3% (1)
- C7% (2)
- D90% (26)
Explanation
Reputable forensic disk imaging tools are required to compute a cryptographic hash (e.g., MD5 or SHA-1) of the complete bit-stream copy to verify integrity and prove the image has not been altered. Option D states the tool 'should NOT compute a hash value,' which is the opposite of a valid requirement - making it the correct choice as 'not a part' of proper imaging tool requirements. Options A (not altering original content), B (logging I/O errors), and C (withstanding peer/scientific review) are all legitimate, accepted requirements for forensic imaging tools.
Topics
Community Discussion
No community discussion yet for this question.