nerdexam
EC-Council

312-49V11 · Question #178

A digital forensics investigator is tasked with analyzing a compromised Mac computer recovered from a cybercrime scene. However, upon examination, the investigator discovers that the log messages…

The correct answer is D. Data manipulation. This scenario directly aligns with CHFI v11 objectives under Anti-Forensics Techniques, specifically techniques used to alter or destroy forensic artifacts to obstruct investigations. Log files on macOS systems--such as system logs, application logs, and security logs--are…

Defeating Anti-Forensics Techniques

Question

A digital forensics investigator is tasked with analyzing a compromised Mac computer recovered from a cybercrime scene. However, upon examination, the investigator discovers that the log messages containing crucial evidence have been tampered with or deleted. Given the tampering or deletion of log messages on the Mac computer, which anti-forensic technique is likely employed to hinder the forensic analysis process in this scenario?

Options

  • AData encryption
  • BData obfuscation
  • CData hiding
  • DData manipulation

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    11% (2)
  • C
    6% (1)
  • D
    78% (14)

Explanation

This scenario directly aligns with CHFI v11 objectives under Anti-Forensics Techniques, specifically techniques used to alter or destroy forensic artifacts to obstruct investigations. Log files on macOS systems--such as system logs, application logs, and security logs--are critical sources of evidence that help investigators reconstruct user activity, detect intrusions, and build event timelines. When an attacker alters, deletes, or modifies log entries, the anti-forensic technique employed is classified as data manipulation. CHFI v11 defines data manipulation as the intentional modification, deletion, or corruption of data or metadata to mislead investigators or erase traces of malicious activity. Log tampering is a classic example, as attackers often remove evidence of unauthorized access, privilege escalation, or persistence mechanisms. Data encryption would make logs unreadable but not selectively altered or deleted. Data hiding involves concealing information in alternate locations (e.g., steganography or hidden files), while data obfuscation focuses on making data confusing but still present. In contrast, the complete deletion or alteration of log messages is a deliberate attempt to falsify or erase evidence. Therefore, consistent with CHFI v11 anti-forensics classifications, data manipulation is the correct and most accurate answer.

Topics

#anti-forensics#log tampering#data manipulation#Mac forensics

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice