オンライン ゲーム会社がランサムウェア攻撃の影響を受けました。従業員が、会社が発行したファイアウォールでの SMS 攻撃を介して受信した添付ファイルを開きました。モバイル デバイスのフォレンジック分析に役立つ次のアクションはどれですか? (2 つ選択)。
正解:C,E
Documenting the respective chain of custody and performing a memory dump of the mobile device for analysis would help during the forensic analysis of the mobile device. The chain of custody is a record of who handled the evidence, when, where, how, and why. The chain of custody helps to preserve the integrity and admissibility of the evidence by preventing tampering, alteration, or loss1. A memory dump is a process of capturing and storing the contents of the device's memory (RAM) for analysis. A memory dump can help to recover volatile data that may be lost when the device is powered off or rebooted, such as running processes, network connections, encryption keys, or malware traces2.