An incident response team is investigating a potential insider threat. An employee is suspected of copying sensitive data to personal cloud storage. Which artifact most directly evidences this activity on a Windows system?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because browser history shows cloud storage site visits, LNK (shortcut) files in Recent Items show which files were recently accessed, Windows Search indexes capture file metadata, and network logs showing large HTTPS uploads to cloud service IPs together build a coherent evidentiary picture of data staging and exfiltration. A is wrong because logon timestamps show when the user was logged in but do not directly evidence file copying or uploads.
Full explanation below image
Full Explanation
B is correct because browser history shows cloud storage site visits, LNK (shortcut) files in Recent Items show which files were recently accessed, Windows Search indexes capture file metadata, and network logs showing large HTTPS uploads to cloud service IPs together build a coherent evidentiary picture of data staging and exfiltration. A is wrong because logon timestamps show when the user was logged in but do not directly evidence file copying or uploads. C is wrong because the Windows Update log tracks OS patches and updates, not user file activity. D is wrong because email archives might contain supporting evidence but would not directly evidence file uploads to cloud storage.