セキュリティアナリストは、侵害されてデータ作成マシンとして使用された1台のサーバーと、作成されたハードドライブのいくつかを特定しました。次のうち、マシンがいつどのように侵害されたか、マルウェアがどこにあるかについての情報を提供する可能性が最も高いのはどれですか?
正解:A
System timeline reconstruction is a forensic analysis technique that involves creating a chronological record of events that occurred on a system based on various sources of evidence such as log files, registry entries, file timestamps, network traffic, etc. System timeline reconstruction can provide information about when and how the machine was compromised and where the malware is located by showing when suspicious activities or changes took place on the system, such as unauthorized access attempts, file creation or modification, process execution, network connections, etc.