Reference no: EM131230040
This week you are reading and watching about the forensic tools used by Computer Forensics Examiners. While the two most popular tools are Guidance Software's EnCase and AccessData's FTK, there are other tools that are available and should be part of your toolbox. Once you have properly identified and collected digital evidence, the next step is to analyze it. It does not really matter if you are performing analysis as part of a criminal investigation or as part of a corporate investigation; you should always follow the same protocols. An emphasis in this course is on helping you understand why using an analysis protocol is important. Remember, you should NEVER, EVER work on original evidence, if it can be avoided by any means; instead, use a forensic image. When you work on the image, you pick the tools you will use. Again, it does not matter which tool you actually use, as long as the tool is accepted by the forensic community, and you are able to testify to the tool's validity, as well as the process you used in your examination.
During your analysis, you should document every step you take and all of your findings. Some tools have a report function that works well to capture both the identified data and the date/time of your various analyses. However, this should always be supplemented with your own notes and documentation.
This week, I would like you to discuss why you need to use a write blocker (either hardware or software) in your examinations, whether for a criminal case or a corporate case.
Also, imagine you are a computer forensic examiner receiving a suspect hard disk drive from a detective in your department. The drive was seized properly during a legally executed search warrant. The detective signs the chain of custody log and hands you the drive. Your job is to accept the drive, conduct an analysis, and maintain the drive until trial. Please explain the steps you would take, from receipt until testimony, including the reasons why you would take each step. For example, what would you check for when you sign for the drive on the chain of custody?
Determine output rate that will maximize total gross revenue
: Laurel and Hardy have written a new managerial economics textbook, for which they receive royalty payments of 15 percent of total revenue from book sales. Determine the output rate that will maximize the total gross revenue. At this level of output, ..
|
Each worker is contracted to work five consecutive days
: In an LTL (less-than-truckload) trucking company, terminal docks include casual workers who are temporarily to account for peak loads. At the Omaha dock the minimum demand for casual workers during the 7 days of the week (starting on Monday) is 20, 1..
|
Transmitting a signal on one end and measuring
: Which tool measures cable length by transmitting a signal on one end and measuring the time it takes for the reflection to reach the end of the cable? Which structured cabling component provides connectivity to computer equipment in the nearby work..
|
What are the advantages of new methodology
: In the past, the medical center has aggregated all facilities costs, and then allocated the total amount on the basis of square footage. What are the advantages and disadvantages of the new methodology?
|
Computer forensic examiner receiving a suspect
: Also, imagine you are a computer forensic examiner receiving a suspect hard disk drive from a detective in your department. The drive was seized properly during a legally executed search warrant.
|
How long do you think it will take me to get a job
: Christa would start pre-school at 3 years old and kindergarten at 5 years of age. Do you honestly believe that waiting 3 years instead of years is going to make a difference in everything I just said or did you even listen to what I said? Or are y..
|
Expected npv on the basis of the scenario analysis
: What are the project's NPV and IRR - What are the project's most likely, worst-case, and best-case NPVs and what is the project's expected NPV on the basis of the scenario analysis?
|
Was there anything in the organizational culture
: What kind of planning went into the change, if any? How was the planning done? Were there any contingency plans? Was there any resistance to this change (from you or others)? How did it appear? What could have overcome the resistance?
|
Calculate the decay constant and the half-life
: Assuming that the activity obeys an exponential decay law, find the equation that best represents the activity and calculate the decay constant and the half-life.
|