ほとんどの従業員がMacBookを使用している組織でサイバーインシデントが発生した後、アレックスという名のフォレンジック調査員が、影響を受けたMacシステムの1つを分析する任務を負った。アレックスは、システムログ、アーティファクト、ファイルシステム、およびユーザーアクティビティを分析できる包括的なMacフォレンジックツールを必要としている。アレックスはどのようなツールを選ぶべきだろうか。
のお気に入りのツールは?
正解:B
Option B. Magnet AXIOM is the best answer because CHFI v11 explicitly includes MAC Forensic Tools , Collecting and Analyzing macOS Artifacts , Analyzing macOS User Activities , Viewing Log Messages in Mac , and APFS file system analysis as important objectives for operating system forensics.
The question asks for a comprehensive Mac forensic tool that can handle system logs, artifacts, file systems, and user activity. Among the options, Magnet AXIOM is the one that best fits that broad forensic role.
Wireshark is a network traffic analysis tool, not a full Mac forensic suite. Metasploit is a penetration testing and exploitation framework, not an evidence-analysis platform. IDA Pro is used for reverse engineering binaries, which is far narrower than the full-system forensic requirement described here.
Because Alex needs a single tool capable of broad macOS evidence examination, the most suitable CHFI- aligned answer is Magnet AXIOM . It best matches the blueprint's focus on Mac artifact analysis, user activity reconstruction, and forensic tool use across operating systems.