nerdexam
EC-Council

312-49V11 · Question #34

During a cybersecurity investigation involving a data breach at a financial institution, an investigator is tasked with identifying the root cause of the breach and generating a timeline of events…

The correct answer is C. Data analysis. According to the CHFI v11 Forensic Investigation Process and Event Correlation objectives, the forensic technique that enables investigators to reconstruct the sequence of events and determine the root cause of an incident is data analysis. Data analysis is the phase where…

Computer Forensics Investigation Process

Question

During a cybersecurity investigation involving a data breach at a financial institution, an investigator is tasked with identifying the root cause of the breach and generating a timeline of events that led to the incident. The investigator needs to determine which step in the forensic process will help uncover the sequence of activities, including the vulnerabilities exploited, the time of attack, and the specific actions taken by the attacker. Which of the following forensic techniques is most effective for achieving this goal?

Options

  • AData duplication
  • BPhotographing the crime scene
  • CData analysis
  • DData acquisition

How the community answered

(68 responses)
  • A
    12% (8)
  • B
    3% (2)
  • C
    79% (54)
  • D
    6% (4)

Explanation

According to the CHFI v11 Forensic Investigation Process and Event Correlation objectives, the forensic technique that enables investigators to reconstruct the sequence of events and determine the root cause of an incident is data analysis. Data analysis is the phase where collected evidence is examined, correlated, and interpreted to extract meaningful insights about attacker behavior. During data analysis, investigators examine logs, timestamps, file system metadata, registry entries, network traffic, memory artifacts, and security alerts to perform timeline analysis, event correlation, and kill chain reconstruction. CHFI v11 explicitly highlights techniques such as timeline creation, event deconfliction, and correlation analysis as essential for identifying the time of attack, vulnerabilities exploited, methods used, and actions performed by the attacker.

Topics

#data analysis#forensic timeline#incident investigation#root cause analysis

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice