QuestionQ129
Procedures and MethodologyYou are the lead forensic analyst at a digital-forensic firm. A major client, a government agency, has experienced a security breach that resulted in the unauthorized disclosure of classified documents. Initial investigations indicate that the attacker, believed to be an employee, used an anonymous, encrypted email service to send these documents to multiple unidentified recipients.
As part of the investigation, you have obtained disk images from the suspect’s workstation. Your task is to extract and analyze relevant evidence that could help identify the unknown recipients. What should be your initial step?
- A Review the disk image for any signs of a trojan or other malware that could have been used in the data breach.
- B Analyze internet history files for potential traces of the anonymous, encrypted email service.
- C Execute a full search of the disk image for file artifacts related to the anonymous, encrypted email service.
- D Inspect the email client on the disk image for any unencrypted data that could contain the recipient’s information.
Community Discussion