300-215 Question 16
Select 3During an investigation, you discover that an attacker used antiforensic techniques to impede your forensic analysis. Which of the following tactics, techniques, and procedures (TTPs) are examples of antiforensic methods that could have been employed?
- A
Using encryption to disguise malicious files and communications
- B
Clearing Windows Event Logs to erase traces of activity
- C
Deploying a honeypot to mislead forensic investigators
- D
Modifying file metadata to falsify timestamps
- E
Utilizing tools like Cisco Secure Endpoint to detect and block threats
Show answer and explanation
Correct answers: A, B, D
Explanation
Antiforensic tactics are methods used by attackers to hinder or mislead forensic investigations. These techniques include encryption to conceal data, log clearing to remove evidence, and metadata manipulation to tamper with forensic timelines. Understanding these TTPs helps incident responders identify when such methods have been employed and develop strategies to counteract them.
- A. Correct.
Using encryption is a common antiforensic tactic as it makes malicious files or communications inaccessible without the decryption key, obstructing forensic analysis.
- B. Correct.
Clearing Windows Event Logs is an antiforensic technique to erase evidence of malicious activity, making it difficult for investigators to trace the attacker’s actions.
- C. Incorrect.
Deploying a honeypot is not considered an antiforensic tactic; it is a defensive cybersecurity strategy used to detect and analyze malicious activities.
- D. Correct.
Modifying file metadata, such as falsifying timestamps, is a classic antiforensic method to mislead investigators about the timeline of events.
- E. Incorrect.
Utilizing tools like Cisco Secure Endpoint is a proactive cybersecurity measure and not an antiforensic technique.