Forensic Checksums and Data Integrity

Answer Correct answer: D — The analyst is practicing integrity by using a checksum to ensure the email file has not been altered.

During a forensic investigation, an analyst uses software to create a checksum of the affected subject's email file. Which of the following is the analyst practicing?

  1. Chain of custody
  2. Data recovery
  3. Non-repudiation
  4. Integrity Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the ability to distinguish between different security concepts by identifying that checksums are specifically used to verify data integrity rather than other attributes like non-repudiation or chain of custody.

Creating a checksum verifies that digital evidence has not been altered, ensuring data integrity. This process is essential for maintaining the validity of forensic investigations.

Learners often confuse integrity with non-repudiation because both involve verification. However, non-repudiation proves who sent data (usually via digital signatures), while integrity proves the data hasn't changed.

Community Discussion (5 comments)

aquarshie 👍 1
Checksum = Integrity
shady23 👍 1 Selected: D
D. Integrity
salah112 👍 2 Selected: D
D. Integrity Creating a checksum of the affected subject's email file is an action that verifies the integrity of the file. In digital forensics, the process of creating a checksum involves generating a hash value (checksum) for a file. If the file remains unchanged, the hash value should remain consistent. If any alterations occur in the file, the hash value would differ, indicating a potential integrity issue.
Hs1208 👍 4 Selected: D
Checksum = Integrity
[Removed] 👍 4 Selected: D
The analyst is looking at the checksum. A checksum is repeating a message and checking the hashes to make sure that the hash from the original message is the same, hence maintaining integrity. correct me if I'm wrong.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Integrity ensures that data has not been altered or tampered with during storage or transmission. In forensics, creating a checksum (hash) provides a mathematical representation of the file's contents; if even a single bit changes, the hash value will differ completely, proving the file's integrity was maintained.

Why the Other Options Are Wrong

Chain of custody tracks the physical handling and transfer of evidence, not its content state. Data recovery focuses on retrieving lost or deleted files, which is distinct from verifying existing ones. Non-repudiation prevents a user from denying their actions, typically requiring cryptographic signatures rather than simple checksums.

Community Comment Notes

The community overwhelmingly agrees on this answer. Comments such as "Checksum = Integrity" highlight the direct association learners should make between these terms. One commenter noted that checking hashes ensures they match the original message, reinforcing the concept of consistency.

Exam Strategy

When you see 'checksum', 'hash', or 'verify unchanged', think immediately of Integrity. When you see 'digital signature' or 'PKI', think Non-repudiation. Keep these definitions distinct for the exam.

Frequently Asked Questions

Why isn't this non-repudiation?

Non-repudiation proves the identity of the sender (who did it). Checksums only prove the file content hasn't changed (what happened).

What is the difference between integrity and chain of custody?

Integrity is about the data's technical state (unchanged). Chain of custody is the legal documentation of who handled the evidence.

Related Analysis

← Back to SY0-601 Study Guide