We used to guess the key, setting the keylength to 4 as this was said in the briefing.
We then used to XOR the file with the key 5a 41 99 bb
It says it determines a .zip file, but when unzipping you realise it's a .docx file so change the extension to get:
flag{xor_is_not_for_security}