企業環境において、不正なデータアクセスの兆候が見られたことを受け、上級幹部のAndroidスマートフォンが内部フォレンジック調査のために保護されました。この調査は管理上のものであり、幹部は調査への協力のために待機しています。デバイスはパスコードで保護されており、潜在的な証拠への即時アクセスはできません。調査担当者は、既存のデータを変更したり、高度な技術的措置を講じたりすることなく、アクセス権を取得する必要があります。証拠の完全性を維持しながら合法的に調査を進めるには、どの方法が最も適切でしょうか?
正解:A
Option A is the most appropriate answer because CHFI v11 places strong emphasis on legal compliance, seeking consent, preserving evidence, chain of custody, and following a sound forensic process . In this scenario, the matter is administrative , the device owner is available , and investigators need access without altering data or resorting to more intrusive technical actions. Under those conditions, obtaining the employee' s voluntary cooperation and passcode disclosure is the most defensible and least disruptive method. The blueprint explicitly includes seeking consent , best practices for handling digital evidence , preserving evidence , and chain of custody under legal and procedural requirements.
This answer also aligns with CHFI's mobile forensics areas covering mobile phone evidence analysis, data acquisition methods, logical and physical acquisition of Android devices, and challenges in mobile forensics . Investigators should first use the least destructive, most lawful, and most forensically sound approach before considering advanced acquisition techniques.
Option B is too intrusive for this fact pattern, C alters device state, and D escalates unnecessarily when consent-based access is already available.