ワシントン州シアトルの病院で発生しているランサムウェア攻撃において、捜査官は厳しい時間的制約の中でストリーミングログを分析し、出力結果に基づいて判断を下さなければならない。この要件に合致するログのフォレンジック調査のカテゴリーはどれか?
正解:A
Answer A is correct because the question explicitly describes analysis during an active incident, with logs being examined as they stream in and findings generated immediately to support operational decisions. That is the definition of real-time log analysis, not postmortem review. CHFI v11 covers both postmortem and real- time analysis, and this distinction is important in exam scenarios. Real-time analysis is used when the incident is still unfolding and investigators need immediate visibility into attacker behavior, system impact, and response priorities. Postmortem analysis, by contrast, happens after the event and is focused on understanding what already occurred. Option B describes a later reporting or lessons-learned outcome, and option D is too generic to represent a specific examination category. In a ransomware crisis, streaming evidence must often be reviewed continuously to guide containment, isolate affected systems, and identify ongoing malicious actions. Since the scenario emphasizes active attack conditions and immediate analytical output, the correct CHFI-aligned category is real-time analysis. That is the only choice that matches both the timing and purpose of the examination described.