nerdexam
EC-Council

312-49 · Question #350

If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?

The correct answer is D. Nothing in particular as these can be operational files. While the t0rn rootkit is known to drop files with similar-sounding names, finding files named 'Zer0.tar.gz' and 'copy.tar.gz' alone is not conclusive evidence of compromise. These could legitimately be backup archives or operational files created by an administrator. Forensic co

Submitted by haruto_sh· Apr 18, 2026Computer Forensics Investigation Process

Question

If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?

Options

  • AThe system has been compromised using a t0rnrootkit
  • BThe system administrator has created an incremental backup
  • CThe system files have been copied by a remote attacker
  • DNothing in particular as these can be operational files

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • D
    88% (22)

Explanation

While the t0rn rootkit is known to drop files with similar-sounding names, finding files named 'Zer0.tar.gz' and 'copy.tar.gz' alone is not conclusive evidence of compromise. These could legitimately be backup archives or operational files created by an administrator. Forensic conclusions must be based on corroborating evidence (file hashes, unexpected processes, modified system binaries, etc.), not filenames alone. Jumping to the conclusion that the system has a rootkit (A) or was attacked (C) based solely on file names would be an investigative error.

Topics

#File analysis#Evidence interpretation#Forensic methodology

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice