nerdexam
EC-Council

312-49V11 · Question #129

James, a forensic investigator, is tasked with examining a suspect's computer system that is believed to have been used for illegal activities. During his investigation, he finds multiple files with…

The correct answer is B. Document the file's existence and send it for decryption by a specialized service. This scenario aligns with CHFI v11 objectives under Anti-Forensics Techniques and Best Practices for Handling Digital Evidence. Encrypted and password-protected files are commonly used as anti-forensic techniques to conceal illicit data and delay investigations. CHFI v11…

Digital Evidence Handling

Question

James, a forensic investigator, is tasked with examining a suspect's computer system that is believed to have been used for illegal activities. During his investigation, he finds multiple files with unusual extensions and encrypted contents. One of the files, in particular, appears to be a password-protected ZIP file. As part of his investigation, James needs to extract and analyze the contents of this file to check if it contains any evidence of criminal activity. What should James do next?

Options

  • AUse a brute force tool to attempt to break the password
  • BDocument the file's existence and send it for decryption by a specialized service
  • CImmediately delete the file to prevent any tampering
  • DOpen the file without using a password and extract the contents

How the community answered

(55 responses)
  • A
    5% (3)
  • B
    80% (44)
  • C
    11% (6)
  • D
    4% (2)

Explanation

This scenario aligns with CHFI v11 objectives under Anti-Forensics Techniques and Best Practices for Handling Digital Evidence. Encrypted and password-protected files are commonly used as anti-forensic techniques to conceal illicit data and delay investigations. CHFI v11 stresses that forensic investigators must follow proper legal, ethical, and procedural guidelines when dealing with encrypted evidence to ensure evidence integrity and admissibility. When an investigator encounters a password-protected archive, the first priority is to preserve the evidence and maintain a clear chain of custody. Documenting the file's existence, metadata, hash values, and storage location is essential. Sending the file to a specialized decryption or cryptanalysis service--often operating under legal authorization--ensures that decryption efforts are conducted lawfully, forensically sound, and without altering the original evidence.

Topics

#encrypted files#password-protected ZIP#forensic procedures#evidence handling

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice