312-49V11 · Question #137
In an investigation of cybercrime involving advanced persistent threats (APTs), the forensic team faces challenges in managing and interpreting the digital evidence due to the global origin of the…
The correct answer is A. Invest in powerful automated tools to handle the high complexity of digital evidence. APT investigations generate massive, complex, multi-source evidence (endpoints, cloud, network telemetry, diverse devices). Automated tools help scale parsing, correlation, triage, timeline building, and artifact extraction. International collaboration (C) is helpful, but the…
Question
In an investigation of cybercrime involving advanced persistent threats (APTs), the forensic team faces challenges in managing and interpreting the digital evidence due to the global origin of the crime and the diverse nature of the digital devices involved. The investigator has to select the most effective method to overcome these challenges. What should be the preferred approach?
Options
- AInvest in powerful automated tools to handle the high complexity of digital evidence
- BOpt for traditional investigation approaches that examine local physical devices
- CImprove collaboration with international law enforcement agencies to bridge the gap in
- DSpeed up the investigation process by bypassing the need for warrants and authorizations
How the community answered
(19 responses)- A79% (15)
- B5% (1)
- D16% (3)
Explanation
APT investigations generate massive, complex, multi-source evidence (endpoints, cloud, network telemetry, diverse devices). Automated tools help scale parsing, correlation, triage, timeline building, and artifact extraction. International collaboration (C) is helpful, but the question focuses on managing/understanding complex evidence efficiently.
Topics
Community Discussion
No community discussion yet for this question.