Computer Hacking Forensic Investigator (CHFI v10) — Question 390

During a high-stakes corporate espionage case, an investigator seeks digital evidence to reveal unauthorized data access and leakage. The investigator possesses the skills to recover deleted files, decrypt encrypted files, and inspect hidden files. Given the availability of multiple potential evidence sources, which category of files is most likely to yield the most valuable information in this scenario?

Answer options

Correct answer: C

Explanation

User-Protected Files are likely to contain sensitive information that has been intentionally secured, making them a prime target for unauthorized access. In contrast, User-Created Files and Computer-Created Files may not hold the same level of confidential data, while files on peripheral devices may not be as directly linked to the unauthorized activities being investigated.