exam questions

Exam CAS-005 All Questions

View all questions & answers for the CAS-005 exam

Exam CAS-005 topic 1 question 49 discussion

Actual exam question from CompTIA's CAS-005
Question #: 49
Topic #: 1
[All CAS-005 Questions]

Which of the following is the best reason for obtaining file hashes from a confiscated laptop?

  • A. To prevent metadata tampering on each file
  • B. To later validate the integrity of each file
  • C. To generate unique identifiers for each file
  • D. To preserve the chain of custody of files
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
vicbersong
1 week, 1 day ago
Selected Answer: B
❌ Why the other options are incorrect: A. To prevent metadata tampering on each file Hashes don't prevent tampering — they detect it. C. To generate unique identifiers for each file Hashes can serve as identifiers, but the main purpose in forensics is to verify integrity. D. To preserve the chain of custody of files Chain of custody refers to tracking who has handled the evidence, not to hashing the files
upvoted 1 times
...
vicbersong
1 week, 1 day ago
Selected Answer: B
✅ B. To later validate the integrity of each file 🔍 Explanation: Obtaining file hashes (like MD5, SHA-1, or SHA-256) from a confiscated laptop is a forensic best practice used to: Ensure files have not been altered since the time of seizure. Validate the integrity of the data at later stages of an investigation or in court. By comparing the original hash values to those calculated later, investigators can prove the files remain unchanged, maintaining their evidentiary value.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago