100-160 Question 235
Single answerDuring an investigation of a suspected insider threat, a cybersecurity team is tasked with identifying the source of a data breach. They decide to analyze log files, recover deleted files, and examine metadata from compromised systems. What is the primary purpose of these digital forensics activities in the context of attack attribution?
- A
To identify vulnerabilities in the system's architecture
- B
To trace the origin and perpetrator of the attack
- C
To improve the network's performance and efficiency
- D
To simulate the attack for future training purposes
Show answer and explanation
Correct answer: B
Explanation
Digital forensics is a critical process in cybersecurity investigations, aimed at collecting, preserving, and analyzing evidence to determine how an attack occurred and who was responsible. In the context of attack attribution, the primary purpose is to trace the origin and identify the perpetrator, enabling organizations to respond effectively and potentially take legal or remedial action.
- A. Incorrect.
Identifying vulnerabilities is part of risk assessment and mitigation, not the primary focus of digital forensics in attack attribution.
- B. Correct.
Tracing the origin and perpetrator of the attack is the main goal of digital forensics in the context of attack attribution. This involves collecting evidence to determine who was responsible and how the attack occurred.
- C. Incorrect.
Improving network performance is unrelated to the objectives of digital forensics and attack attribution.
- D. Incorrect.
Simulating the attack is useful for training, but it is not the purpose of digital forensics during an investigation.