312-49V11 · Question #125
During a live data acquisition procedure, forensic investigators are tasked with analyzing a suspected breach of a corporate network. The breach involves unauthorized access to sensitive files…
The correct answer is C. Open connections and routing information. This question directly maps to CHFI v11 objectives under Data Acquisition and Duplication, specifically live data acquisition and the order of volatility. Live forensics is critical when systems cannot be powered down without losing crucial evidence, particularly during active…
Question
During a live data acquisition procedure, forensic investigators are tasked with analyzing a suspected breach of a corporate network. The breach involves unauthorized access to sensitive files stored on the company's servers. Investigators aim to gather volatile data to trace the origin of the breach and identify potential network vulnerabilities. In a live data acquisition scenario, which types of volatile data would investigators prioritize capturing to trace the intrusion's origin and identify network vulnerabilities?
Options
- APrinter driver versions and configurations
- BCurrent system uptime and DLLs loaded
- COpen connections and routing information
- DMouse click activity and cursor movements
How the community answered
(26 responses)- A4% (1)
- B19% (5)
- C69% (18)
- D8% (2)
Explanation
This question directly maps to CHFI v11 objectives under Data Acquisition and Duplication, specifically live data acquisition and the order of volatility. Live forensics is critical when systems cannot be powered down without losing crucial evidence, particularly during active or recent network intrusions. CHFI v11 emphasizes that investigators must prioritize volatile data that can quickly disappear when a system is shut down or network conditions change. Open network connections, active sessions, routing tables, ARP cache, and listening ports provide immediate insight into how an attacker accessed the system, whether lateral movement occurred, and which external or internal IP addresses were involved. Capturing this data helps investigators trace the intrusion's origin, identify command-and-control communications, and uncover misconfigurations or exposed services that enabled the breach.
Topics
Community Discussion
No community discussion yet for this question.