QuestionQ129

Procedures and Methodology

You are the lead forensic analyst at a digital-forensic firm. A major client, a government agency, has experienced a security breach that resulted in the unauthorized disclosure of classified documents. Initial investigations indicate that the attacker, believed to be an employee, used an anonymous, encrypted email service to send these documents to multiple unidentified recipients.

As part of the investigation, you have obtained disk images from the suspect’s workstation. Your task is to extract and analyze relevant evidence that could help identify the unknown recipients. What should be your initial step?

  • A Review the disk image for any signs of a trojan or other malware that could have been used in the data breach.
  • B Analyze internet history files for potential traces of the anonymous, encrypted email service.
  • C Execute a full search of the disk image for file artifacts related to the anonymous, encrypted email service.
  • D Inspect the email client on the disk image for any unencrypted data that could contain the recipient’s information.
Explanation

Web-browser artifacts are the most direct initial evidence source for a web-based anonymous encrypted email service. Internet history can establish that the service was accessed and provide URLs, timestamps, searches, cached data, and related leads that can guide more focused recovery of service artifacts. NIST identifies browser history, cache, and cookies as relevant digital-forensic artifacts and notes that investigations related to an offense may begin by reviewing Internet history files.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!