Question 5 of 10Pro Only

Explain how file hash analysis works and why MD5, SHA-1, and SHA-256 hashes are important for SOC analysts. How would you use file hashes during an investigation?

Sample answer preview

A file hash is a fixed-length string generated by running a file through a cryptographic hashing algorithm. The hash acts as a unique fingerprint for that file. Even a single byte change in the file produces a completely different hash value.

file hashMD5SHA-1SHA-256VirusTotalcollision attack

Unlock the full answer

Get the complete model answer, key points, common pitfalls, and access to 9+ more SOC Analyst interview questions.

Upgrade to Pro

Starting at $19/month • Cancel anytime