サイバー攻撃を受け、大手eコマースプラットフォームは広範囲にわたるシステムダウンを経験し、甚大な経済的損失と顧客からの信頼失墜につながりました。制御回復に奔走する中で、顧客の機密データが漏洩したことが明らかになり、データセキュリティとプラットフォームの評判が脅かされました。eコマースプラットフォームへのサイバー攻撃の余波の中で、フォレンジック対策の不足に起因するものではないのは、次のうちどれでしょうか?
正解:B
According to the CHFI v11 objectives under Computer Forensics Fundamentals , Forensic Readiness , and Incident Response Integration , forensic readiness refers to an organization's ability to efficiently collect, preserve, analyze, and present digital evidence while minimizing the cost and impact of investigations. A lack of forensic readiness primarily affects how well an organization can respond to, investigate, and legally defend itself after an incident-not whether the incident causes operational disruption.
System downtime (Option B) is a direct operational impact of a cyberattack , such as a DDoS attack, ransomware infection, or system compromise. While poor preparedness may prolong recovery, downtime itself is not caused by the absence of forensic readiness; it is caused by the attack's technical and operational effects. Therefore, system downtime is not a consequence of lacking forensic readiness.
In contrast, the other options are well-documented consequences of poor forensic readiness in CHFI v11.
Lack of preparation often results in inability to collect legally sound evidence (Option D), which affects court admissibility. Limited collaboration with legal and IT teams (Option C) occurs when roles, procedures, and escalation paths are not predefined. Additionally, without proper controls and monitoring, data manipulation, deletion, and theft (Option A) may go undetected or untraceable.
The CHFI Exam Blueprint v4 emphasizes forensic readiness as a strategic capability focused on evidence integrity, compliance, and investigative efficiency , not on preventing or causing system downtime, making Option B the correct and exam-aligned answer