nerdexam
EC-Council

312-49V11 · Question #152

During a forensic investigation of a system suspected to be involved in cybercrime, the investigator observes discrepancies between the $STANDARD_INFORMATION and $FILE_NAME creation dates for some…

The correct answer is D. The timestamps for some files have been manipulated, possibly as an anti-forensic measure. Differences between NTFS $STANDARD_INFORMATION and $FILE_NAME timestamps are a known indicator of timestamp manipulation. The presence of BCWipe (a secure deletion/privacy tool) strengthens the inference of anti-forensic activity aimed at obscuring timelines and evidence.

Defeating Anti-Forensics Techniques

Question

During a forensic investigation of a system suspected to be involved in cybercrime, the investigator observes discrepancies between the $STANDARD_INFORMATION and $FILE_NAME creation dates for some files. As part of the investigation process, the investigator also noted that a utility called BCWipe was found installed on the system. What would be the investigator's most plausible conclusion based on these observations?

Options

  • AThe system user used BCWipe to delete specific files securely
  • BThe system was compromised with malware that altered the metadata
  • CThe files were encrypted using the BCWipe utility
  • DThe timestamps for some files have been manipulated, possibly as an anti-forensic measure

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    14% (3)
  • C
    5% (1)
  • D
    76% (16)

Explanation

Differences between NTFS $STANDARD_INFORMATION and $FILE_NAME timestamps are a known indicator of timestamp manipulation. The presence of BCWipe (a secure deletion/privacy tool) strengthens the inference of anti-forensic activity aimed at obscuring timelines and evidence.

Topics

#anti-forensics#timestamp manipulation#BCWipe#NTFS metadata discrepancy

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice