Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium

A SOC analyst is performing a forensic investigation on a compromised Linux server. The attacker is suspected to have deleted log files and other evidence. To uncover the attacker's activity, the analyst needs to examine areas of the disk that are not currently allocated to active files but may still contain remnants of deleted data. Which forensic technique is the analyst employing?

  1. AFile System Carving
  2. BLive Forensics
  3. CMemory Forensics
  4. DNetwork Forensics
Show answer & explanation

Correct answer: A. File System Carving

File system carving, also known as data carving, is the process of extracting files or data fragments from unallocated space on a storage device, which is crucial when an attacker has attempted to delete evidence.

Why the other options are wrong

  • B. Live forensics collects data from a running system, but the question focuses on deleted data remnants on disk.
  • C. Memory forensics involves analyzing the contents of RAM, not deleted files on disk.
  • D. Network forensics analyzes network traffic, not data on a compromised host's disk.

File System Carving

A digital forensic technique used to recover deleted or damaged files and data fragments from unallocated space on a storage medium.

  • Searches for file headers and footers.
  • Useful when attackers attempt to erase evidence.
  • Can recover partial files even without file system metadata.

Memory trick: Memory, Live, Carve, Network – what are you looking for?

More Security Operations questions