Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

EC-Council 112-57 Exam - Topic 12 Question 1 Discussion

Which of the following techniques is used to compute the hash value for a given binary code to uniquely identify malware or periodically verify changes made to the binary code during analysis?
A) File fingerprinting
B) Strings search
C) Local and online malware scanning
D) Malware disassembly

EC-Council 112-57 Exam - Topic 12 Question 1 Discussion

Actual exam question for EC-Council's 112-57 exam
Question #: 1
Topic #: 12
[All 112-57 Questions]

Which of the following techniques is used to compute the hash value for a given binary code to uniquely identify malware or periodically verify changes made to the binary code during analysis?

Show Suggested Answer Hide Answer
Suggested Answer: A

File fingerprinting is the forensic technique of generating a cryptographic hash (such as MD5, SHA-1, SHA-256) for a file to create a unique, repeatable identifier for that exact byte sequence. In malware forensics, analysts compute hashes to (1) uniquely identify a suspicious binary across cases and tools, (2) confirm whether two samples are identical or different variants, and (3) verify integrity over time---for example, ensuring the sample did not change during copying, extraction, sandbox handling, or during an analysis workflow that might inadvertently modify the file (e.g., patching, unpacking outputs, or tool-side normalization). Re-hashing at different stages provides a defensible way to demonstrate that the analyzed artifact is the same as the acquired artifact, supporting evidentiary integrity and chain-of-custody principles commonly emphasized in digital forensics documentation.

The other techniques do not primarily serve this purpose. Strings search extracts readable text fragments but does not produce a unique integrity identifier. Local and online malware scanning uses signatures/reputation and may identify families, but it is not an integrity verification mechanism for the exact file bytes. Malware disassembly helps understand logic and instructions, not compute an identity hash. Therefore, the correct answer is File fingerprinting (A).


Contribute your Thoughts:

0/2000 characters
Joaquin
25 days ago
D) Malware disassembly is useful, but not for hashing specifically.
upvoted 0 times
...
Rikki
1 month ago
A) File fingerprinting is more reliable for hash values.
upvoted 0 times
...
Zoila
1 month ago
I agree, but B) Strings search can also help in identifying malware.
upvoted 0 times
...
Lorean
1 month ago
I think A) File fingerprinting is the right answer. It uniquely identifies files.
upvoted 0 times
...
Carmen
2 months ago
But strings search isn’t as reliable for unique identification as file fingerprinting.
upvoted 0 times
...
Alline
2 months ago
I’m not so sure. B) Strings search can also help in identifying patterns.
upvoted 0 times
...
Keneth
2 months ago
I agree! File fingerprinting is effective for tracking changes.
upvoted 0 times
...
Jodi
2 months ago
I think it's A) File fingerprinting. It’s the best way to uniquely identify malware.
upvoted 0 times
...
Edison
2 months ago
But B) Strings search doesn’t uniquely identify like A) File fingerprinting does.
upvoted 0 times
...
Aileen
2 months ago
I’m not so sure. B) Strings search can also be useful for identifying patterns.
upvoted 0 times
...
Dianne
3 months ago
I agree, A) File fingerprinting is the best choice. It helps track changes effectively.
upvoted 0 times
...
Golda
3 months ago
I think it's A) File fingerprinting. It’s essential for unique identification.
upvoted 0 times
...
Martina
3 months ago
D) Malware disassembly is important too, but not for hashing.
upvoted 0 times
...
Alaine
3 months ago
Surprised that people don’t know this, it’s basic stuff!
upvoted 0 times
...
Theodora
5 months ago
I thought C) Local and online malware scanning was the answer?
upvoted 0 times
...
Kristine
5 months ago
Totally agree, it’s essential for malware detection.
upvoted 0 times
...
Theodora
5 months ago
A) File fingerprinting is the right choice!
upvoted 0 times
...
Page
5 months ago
File fingerprinting is definitely the most efficient method here!
upvoted 0 times
...
Tammi
5 months ago
I thought disassembly was more about understanding the code, not hashing.
upvoted 0 times
...
Selma
5 months ago
Wait, are we sure it's not C? Scanning seems relevant too.
upvoted 0 times
...
Ronna
6 months ago
Totally agree, it's all about unique identifiers.
upvoted 0 times
...
Sheridan
6 months ago
A) File fingerprinting is the right choice!
upvoted 0 times
...
Gregoria
6 months ago
I feel like I’ve seen this in our notes, and A) File fingerprinting sounds familiar, but I’m not 100% confident about it.
upvoted 0 times
...
Tawna
6 months ago
I’m a bit confused because I thought malware disassembly could also help identify changes, but I guess that’s not the same as computing a hash value?
upvoted 0 times
...
Brinda
6 months ago
I remember practicing a question similar to this, and I think hashing is definitely related to identifying malware, so A seems likely.
upvoted 0 times
...
Dominic
6 months ago
I think the answer might be A) File fingerprinting, but I'm not entirely sure if that's the right term for computing hash values.
upvoted 0 times
...

Save Cancel