あなたは、機密データの漏洩の可能性を調査している大手テクノロジー企業で、コンピュータフォレンジック調査官として働いています。最重要容疑者は、最近退職した従業員です。会社は、容疑者の業務用ノートパソコン(Windows OS搭載)を押収しました。あなたの責任は、調査に必要なデータを取得することです。事件の重大性を考慮すると、証拠の完全性を維持しなければなりません。システムはまだ稼働しており、揮発性データの収集が最優先事項です。揮発性データを収集するための最も正確な手順は何ですか?
正解:B
Option B is the best answer because CHFI v11 explicitly covers Live Acquisition , Order of Volatility , Rules of Thumb for Data Acquisition , and Collecting Volatile Information and Non-Volatile Information . When a Windows system is still running, the investigator should gather the most volatile and easily lost information first .
Among the choices provided, network connections should be collected first because they can disappear immediately if sessions close or the system state changes. Running processes come next because active processes may terminate or change quickly. A list of open ports is also volatile and supports network-state interpretation, but it is slightly less informative on its own than established connections and active processes.
System state is collected after those more transient live indicators.
This ordering is consistent with CHFI's emphasis on preserving volatile evidence before it is altered by shutdown, user activity, or acquisition actions. Although detailed live-response procedures can vary by tool and environment, the option that best matches CHFI's order-of-volatility principle is: network connections, running processes, open ports, then system state .