EC-Council
312-49 · Question #425
If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?
Sign in or unlock 312-49 to reveal the answer and full explanation for question #425. The question stem and answer options stay visible for context.
Submitted by khalil_dz· Apr 18, 2026Disk Forensics
Question
If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?
Options
- AThe system files have been copied by a remote attacker
- BThe system administrator has created an incremental backup
- CThe system has been compromised using a t0rn rootkit
- DNothing in particular as these can be operational files
Unlock 312-49 to see the answer
You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#File analysis#Linux forensics#Rootkit indicators#Forensic methodology