Question #1
A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator wants to demonstrate that the suspect did indeed visit these sites. However, the suspect has cleared the search history and emptied the cookie cache. Moreover, he has removed any images he might have downloaded. What can the investigator do to prove the violation?
Answer: A
Option Analysis:
A. Correct, forensic imaging of the disk preserves the original storage state, and deleted web cache files, browsing history fragments, and erased downloaded images can typically be recovered from unallocated disk space even after the suspect cleared history and deleted files.
B. Incorrect, co-worker eye-witness testimony is not forensically verifiable evidence of the specific website visits and downloaded content attributed to the suspect.
C. Incorrect, the Windows registry does not store records of individual website visits or downloaded image files, so this will not yield the required evidence of the violation.
D. Incorrect, requesting evidence from website administrators requires legal process, is logistically slow, and cannot directly tie the alleged activity to the suspect's specific device.
Key Concept: The core CHFI v11 concept here is that deleted digital data remains intact on storage media until overwritten, so forensic imaging and deleted file recovery can retrieve evidence of erased user activity including web browsing and downloads.
References:
EC-Council Computer Hacking Forensic Investigator (CHFI) v11 Program Page, https://www.eccouncil.org/programs/computer-hacking-forensic-investigator-chfi/
NIST SP 800-86: Guide to Integrating Forensic Techniques into Incident Response, https://csrc.nist.gov/publications/detail/sp/800-86/final