あなたはデジタルフォレンジック企業の主任フォレンジックアナリストです。あなたの主要顧客の1つである政府機関がセキュリティ侵害を受け、機密文書が不正に漏洩しました。初期調査の結果、攻撃者は従業員であると疑われ、匿名暗号化メールサービスを使用して複数の未知の受信者にこれらの文書を送信したことが判明しました。調査の一環として、容疑者のワークステーションからディスクイメージを入手しました。あなたの任務は、未知の受信者の特定につながる可能性のある関連証拠を抽出し、分析することです。最初にとるべき手順は何ですか?
正解:B
Option B is the best first step because the scenario already points to the use of an anonymous, encrypted email service , and the most direct source of evidence on the disk image is likely to be internet history and browser artifacts associated with access to that service. In forensic investigations, the first priority after acquiring the image is to identify the user's interaction with the suspected communication platform. Browser history, cached pages, cookies, form entries, session remnants, and related web artifacts can reveal service usage patterns, access times, account identifiers, or other traces that help identify unknown recipients or at least narrow the communication path.
Option C is broader and may be useful later, but a full search of all artifacts is less targeted as an initial move.
Option D is weaker because the question specifically refers to an anonymous encrypted email service, which is often web-based rather than tied to a traditional email client. Option A shifts attention to malware without evidence that malware was the primary method of exfiltration. Therefore, the most logical CHFI-style first step is to examine internet history files and related web-use artifacts for traces of the anonymous email activity.