ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 428 - CAS-004 discussion

Report
Export

A forensics investigator is analyzing an executable file extracted from storage media that was submitted (or evidence The investigator must use a tool that can identify whether the executable has indicators, which may point to the creator of the file Which of the following should the investigator use while preserving evidence integrity?

A.
idd
Answers
A.
idd
B.
bcrypt
Answers
B.
bcrypt
C.
SHA-3
Answers
C.
SHA-3
D.
ssdeep
Answers
D.
ssdeep
E.
dcfldd
Answers
E.
dcfldd
Suggested answer: D

Explanation:

ssdeep is a tool that computes and matches Context Triggered Piecewise Hashing (CTPH), also known as fuzzy hashing. It can be used to identify similar files or slight variations of the same file, which may point to the creator of the file if certain patterns or markers are consistently present. This method allows for integrity checking without altering the evidence, which is critical in forensic investigation.

asked 02/10/2024
Alexander Ferrer
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first