nerdexam
EC-Council

312-49V11 · Question #126

A digital forensics team is investigating a cyberattack where multiple devices were compromised. Among the seized devices is an Android smartphone with evidence suggesting interaction with both…

The correct answer is C. To establish a connection between different devices involved in the cyberattack. This scenario aligns with CHFI v11 objectives under Mobile and IoT Forensics and Cross- Platform Digital Evidence Correlation. Modern cyberattacks frequently involve multiple devices and operating systems working together as part of a single attack chain. In mobile forensic…

Mobile Device Forensics

Question

A digital forensics team is investigating a cyberattack where multiple devices were compromised. Among the seized devices is an Android smartphone with evidence suggesting interaction with both Windows and Linux systems. In Android and iOS forensic analysis, why is it important to analyze files associated with Windows and Linux devices?

Options

  • ATo confirm the operating system used on the compromised smartphone
  • BTo identify the manufacturer of the Windows and Linux systems
  • CTo establish a connection between different devices involved in the cyberattack
  • DTo determine the brand and model of the Android smartphone

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    5% (1)
  • C
    79% (15)
  • D
    5% (1)

Explanation

This scenario aligns with CHFI v11 objectives under Mobile and IoT Forensics and Cross- Platform Digital Evidence Correlation. Modern cyberattacks frequently involve multiple devices and operating systems working together as part of a single attack chain. In mobile forensic investigations, Android and iOS devices often store artifacts that reflect interactions with external systems such as Windows and Linux machines. These artifacts may include USB connection logs, file transfer records, SSH keys, shared application data, cloud sync traces, or remnants of malware propagation. CHFI v11 emphasizes the importance of event correlation and timeline analysis across heterogeneous environments. By analyzing Windows-and Linux-related files found on a mobile device, investigators can establish relationships between compromised endpoints, reconstruct attacker movement, and identify how data or malware was transferred between systems. This cross-device correlation is essential for attributing actions, understanding lateral movement, and proving coordinated activity during an incident.

Topics

#mobile forensics#Android forensics#cross-device analysis#cyberattack investigation

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice