ロサンゼルスの小売チェーンでマルウェア感染の疑いのある事件が発生した後、フォレンジック調査官は、侵害されたサーバーのパフォーマンス低下と、不正な外部通信を示唆する兆候を確認した。システムに影響を与える悪意のある活動の存在を立証するために、調査官はまずどのような証拠を調べて、侵害が実際に発生していることを裏付けるべきだろうか?
正解:A
The best answer is A because the scenario already points toward unauthorized external communications, so the strongest first corroborating evidence is abnormal network traffic flow. CHFI v11 emphasizes malware indicators, system and network behavior analysis, and monitoring network activities, ports, and DNS as part of malware forensics. While unknown processes running can also be important, the question specifically asks what should be examined first to substantiate an active compromise when suspicious outbound communications are already suspected. Abnormal traffic flows directly support that hypothesis by showing whether the host is beaconing, exfiltrating data, contacting command-and-control infrastructure, or communicating in patterns inconsistent with normal business operations. Browser configuration changes and general system slowdown are weaker, less direct indicators. Slow performance can occur for many benign reasons, whereas suspicious traffic patterns provide stronger evidence of live malicious activity and can also guide scoping across the environment. In CHFI-style reasoning, when network compromise indicators are already present, the most probative next evidence source is the network behavior itself. That makes abnormal traffic flows the strongest answer.