312-49V11 · Question #152
During a forensic investigation of a system suspected to be involved in cybercrime, the investigator observes discrepancies between the $STANDARD_INFORMATION and $FILE_NAME creation dates for some…
The correct answer is D. The timestamps for some files have been manipulated, possibly as an anti-forensic measure. Differences between NTFS $STANDARD_INFORMATION and $FILE_NAME timestamps are a known indicator of timestamp manipulation. The presence of BCWipe (a secure deletion/privacy tool) strengthens the inference of anti-forensic activity aimed at obscuring timelines and evidence.
Question
During a forensic investigation of a system suspected to be involved in cybercrime, the investigator observes discrepancies between the $STANDARD_INFORMATION and $FILE_NAME creation dates for some files. As part of the investigation process, the investigator also noted that a utility called BCWipe was found installed on the system. What would be the investigator's most plausible conclusion based on these observations?
Options
- AThe system user used BCWipe to delete specific files securely
- BThe system was compromised with malware that altered the metadata
- CThe files were encrypted using the BCWipe utility
- DThe timestamps for some files have been manipulated, possibly as an anti-forensic measure
How the community answered
(21 responses)- A5% (1)
- B14% (3)
- C5% (1)
- D76% (16)
Explanation
Differences between NTFS $STANDARD_INFORMATION and $FILE_NAME timestamps are a known indicator of timestamp manipulation. The presence of BCWipe (a secure deletion/privacy tool) strengthens the inference of anti-forensic activity aimed at obscuring timelines and evidence.
Topics
Community Discussion
No community discussion yet for this question.