高度なデジタルフォレンジック専門家であるジェームズは、オンライン犯罪事件の捜査に取り組んでいる。容疑者は、侵害されたデバイスのネットワークを通じて不正行為を行ったとみられている。証拠はデジタルデータであり、ログ、メタデータ、システム/アプリケーションのタイムスタンプなど、さまざまなシステムにわたる複雑なデータネットワークが残されている。ジェームズは、容疑者のデバイスからメタデータを収集し、システム/アプリケーションのログを精査し、犯罪が行われたとみられる時間帯に発生したファイルや操作のタイムスタンプを分析することに捜査の焦点を絞っている。
ジェームズはデジタル上の痕跡を精査しながら、容疑者と犯罪を直接結びつけるデータ、あるいは発生した出来事を裏付ける証拠となるデータを探し出そうとしている。彼は、メタデータやログからファイルへのアクセス、文書の作成、アプリケーションの使用、ネットワーク活動といった行動が明らかになり、これらが容疑者の行動の時系列を解明するのに役立つことを理解している。この証拠は捜査においてどのような役割を果たすのだろうか?
正解:B
Option B. Corroborative evidence is the best answer because the question describes logs, metadata, and timestamps being used to support and confirm what happened during the incident. CHFI v11 explicitly includes metadata investigation , event logs , timeline and kill chain analysis , and reconstruction of user or system activity through forensic artifacts.
This kind of evidence often does not stand alone as a complete confession-like proof, but it is extremely valuable because it corroborates the sequence of events, supports witness statements, confirms access patterns, and links actions across different systems. For example, file timestamps, logon events, and application logs can help show that a suspect account accessed a document, used a device, or connected to a system at a particular time. That is exactly the role of corroborative evidence.
Option A would help clear the suspect, which is not the focus here. Option C is too absolute because the question emphasizes supporting and reconstructive value. Option D is too narrow. Therefore, under CHFI evidence-analysis principles, the logs, metadata, and timestamps described here serve primarily as corroborative evidence .