nerdexam
EC-Council

212-82 · Question #157

You are investigating a data leakage incident where an insider is suspected of using image steganography to send sensitive information to a competitor. You have also recovered a VeraCrypt volume…

The correct answer is B. H364F9F4FD3H. Explanation Option B (H364F9F4FD3H) is correct because when the VeraCrypt volume file "S3cr3t" is mounted using the password "sniffer@123," the image file contained within the volume reveals the steganographically hidden secret code H364F9F4FD3H upon extraction using…

Submitted by neha2k· Mar 6, 2026Cloud Security Operations & Incident Response

Question

You are investigating a data leakage incident where an insider is suspected of using image steganography to send sensitive information to a competitor. You have also recovered a VeraCrypt volume file S3cr3t from the suspect. The VeraCrypt volume file is available In the Pictures folder of the Attacker Machined. Your task Is to mount the VeraCrypt volume, find an image file, and recover the secret code concealed in the file. Enter the code as the answer. Hint:

If required, use sniffer@123 as the password to mount the VeraCrypt volume file. (Practical Question)

Options

  • AL76D2E8CBA1K
  • BH364F9F4FD3H
  • CJ782C8C2EH6J
  • DG85E2C7AB1R6

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    72% (21)
  • C
    17% (5)
  • D
    7% (2)

Explanation

Explanation

Option B (H364F9F4FD3H) is correct because when the VeraCrypt volume file "S3cr3t" is mounted using the password "sniffer@123," the image file contained within the volume reveals the steganographically hidden secret code H364F9F4FD3H upon extraction using appropriate steganography tools (such as Steghide or OpenStego).

Options A (L76D2E8CBA1K), C (J782C8C2EH6J), and D (G85E2C7AB1R6) are deliberate distractors - they are plausible-looking alphanumeric codes but do not match the actual hidden data extracted from the steganographic image inside the mounted VeraCrypt container; they were crafted to test whether candidates actually performed the practical steps rather than guessing.

Memory Tip

Remember the workflow as "Mount → Find → Extract": Mount the VeraCrypt volume (password: sniffer@123), locate the image file inside, then extract the hidden data using a steganography tool. The answer code H364F9F4FD3H follows a symmetric pattern - it starts and ends with "H" - making it distinguishable from the other options, which begin and end with different letters (L, J, and G/R respectively). This symmetry can help you recall the correct answer under exam pressure.

Topics

#Data Leakage Investigation#Insider Threat#Steganography Analysis#VeraCrypt Forensics

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice