Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 298 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 298
Topic #: 1
[All 312-49v10 Questions]

While searching through a computer under investigation, you discover numerous files that appear to have had the first letter of the file name replaced by the hex code byte 5h. What does this indicate on the computer?

  • A. The files have been marked as hidden
  • B. The files have been marked for deletion
  • C. The files are corrupt and cannot be recovered
  • D. The files have been marked as read-only
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
aqeel1506
4 months, 1 week ago
The correct answer is A. The files have been marked as hidden. In Windows, files with a filename that starts with the hex code byte 5h (which corresponds to the character "E" in ASCII) are considered hidden files. This is a common technique used to hide files from the normal file listing, and is often used by malware or unauthorized users to conceal their activities. Here's a brief overview of the other options: B. The files have been marked for deletion: This would typically involve modifying the file's attributes or moving it to a recycle bin, rather than modifying the file name. C. The files are corrupt and cannot be recovered: There is no indication that the files are corrupt or cannot be recovered. D. The files have been marked as read-only: This would involve modifying the file's attributes, rather than modifying the file name.
upvoted 1 times
...
ala76nl
5 months ago
Selected Answer: B
The discovery of numerous files with the first letter of the file name replaced by the hex code byte 5h indicates that The files have been marked for deletion (Option B). In the context of file systems, especially FAT (File Allocation Table) systems, when a file is deleted, the operating system replaces the first character of the file name with a specific marker (commonly the hex value 0xE5). This marks the file as deleted, but the data remains on the disk until it is overwritten. The hex code byte 5h is often associated with similar behavior, indicating that these files have been flagged for deletion.
upvoted 1 times
...
Elb
5 months, 2 weeks ago
Selected Answer: B
First symbol of the deleted file entry is marked with E5 symbol, so Disk Scanner can assume that this entry has been deleted.
upvoted 1 times
...
Elb
1 year, 4 months ago
B: https://www.ntfs.com/disk-scan.htm
upvoted 1 times
...
viplust
1 year, 4 months ago
Selected Answer: B
From CHFI textbook v10 page 428: The OS replaces the first letter of a deleted file name with a hex byte code: E5h E5h is a special tag that indicates that the file has been deleted
upvoted 1 times
...
Manzer
1 year, 8 months ago
Selected Answer: A
The hex code byte 5h corresponds to the ASCII character "ENQ" which is a control character used in data communication protocols. When the first character of a file name is replaced by the hex code byte 5h, it indicates that the file has been marked as hidden in the file system. In the Windows operating system, files and folders can be marked as hidden to prevent them from being displayed in normal file browsing operations. Hidden files and folders are typically used to store system files or to protect sensitive data from unauthorized access. However, hidden files can still be accessed and manipulated by users with appropriate permissions or tools. Replacing the first character of a file name with a control character like "ENQ" can be used as a way of hiding files from casual inspection, although this is not a foolproof method of concealing files from forensic analysis.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...