ある国際航空会社が最近、予約システムへのサイバー攻撃を発見しました。この攻撃は綿密に計画・実行され、痕跡はほとんど残っていません。攻撃者は、データ難読化やログ操作などの高度なフォレンジック対策技術を使用しており、社内のサイバーセキュリティチームが攻撃の発生源を特定し、その影響全体を把握することは困難です。このような複雑な調査に直面した場合、サイバーセキュリティチームが最初にとるべき行動は次のうちどれでしょうか?
正解:C
Option C is the best first course of action because, in a complex intrusion involving anti-forensics , the investigation must first establish the scope and impact of the breach before deeper reverse engineering or broad remediation decisions are made. CHFI v11 emphasizes the forensic investigation process , including first response , evidence preservation , case analysis , and understanding indicators of compromise and anti-forensics challenges .
Determining exactly what data was compromised is foundational. It helps investigators define the severity of the incident, identify affected systems and stakeholders, prioritize evidence collection, and support legal, regulatory, and business response requirements. Without first establishing the compromised data set, later activities such as reverse engineering attacker methods or deploying broad controls may be less targeted and less effective.
Option A may become important later, but it is not the most immediate first step in understanding breach impact. B and D are response measures, yet prematurely changing the environment can complicate forensic analysis. Therefore, under CHFI's investigation-process and anti-forensics principles, the most appropriate first action is to identify the exact data that has been compromised .