大規模な組織的サイバー攻撃を受け、多国籍企業はベテランのフォレンジック調査員であるリサに調査を依頼した。攻撃は同社のMSSQLサーバーに侵入し、リサは複数のソースと場所から同時に実行された高度なSQLインジェクション攻撃が原因だと疑っていた。攻撃の発生源を特定するため、リサはMSSQLサーバー上の証拠ファイルを収集するだけでなく、調査する必要があった。この攻撃の規模と巧妙さに対処するために、リサはどのツールに頼るべきだろうか?
正解:C
Option C. EnCase is the best answer because the question is about a forensic investigation of an MSSQL server where Lisa needs to collect and examine evidence files in a defensible manner. CHFI v11 explicitly includes SQL Server Logs , Investigating SQL Injection , and broad use of forensic tools for acquisition and examination of digital evidence.
Among the choices, EnCase is the forensic suite most appropriate for evidence collection, preservation, and detailed analysis . It supports imaging, examination, and evidentiary workflow, which are central to determining attack origin in a legally sound way. Sqlmap and SQLsus are offensive or testing-oriented tools associated with SQL injection activity, not primary forensic evidence examination platforms. Nessus is a vulnerability scanner, useful for assessment but not the best answer for collecting and analyzing MSSQL evidence after a breach.
Because the scenario centers on forensic examination of compromised database-server evidence, the strongest CHFI-aligned answer is EnCase , not exploit or scanning tools. It best supports evidence preservation, analysis, and reporting in a large-scale SQL-injection investigation.