Describe exact investigative techniques that you would use

Assignment Help Computer Engineering
Reference no: EM131882709

Assignment

With the identification and preservation of the physical and digital evidence completed the incident response team must now enter the data collection phase. During the data collection phase, the investigative team must collect volatile evidence first, and non-volatile second. Describe the volatile and non-volatile evidence types to be collected and the methods to both collect and analyze the two types of evidence.

• Describe the volatile live acquisition process to collect evidence related to system memory and registry changes and analysis methods conducted over this evidence.

• Describe the non-volatile acquisition process of evidence collection over powered down systems and devices, and the related analysis methods used over non-volatile evidence.

• Describe the exact investigative techniques that you would use to analyze the users' information, habits, and history for each program. Explain the reasons for your selected techniques.

Remember to address forensic evidence you might find relating to the ransomware attack. You should be making references to specific directories, files, file types, registry entries and log files which point to sources of the incident forensic evidence.

The 16-18 slide PowerPoint presentation should include the following:

• Title Slide (1)
• Topics of Discussion Slide (1)
• Windows 10 Operating System (3 slides)
• Registry and Memory (2 slides)
• Internet Explorer (3 slides)
• Outlook e-mail (2 slides)
• Photoshop (2 slides)
• Office (3 slides)
• References Slide (1).

Reference no: EM131882709

Questions Cloud

Describe the communication process : 1. Describe the communication process and distinguish between formal and informal communication.
Analyze what you see in terms of technology and social class : Analyze what you see in terms of technology and social class. Once you complete your observation, post a 2- to 3-paragraph analysis of what you saw.
Identify the parties who are before the court : To challenge you to think about how you would have decided the case. In your case law analyses, you must be able to navigate the court's decision.
Terms of culture and communication : Thinking in terms of culture and communication: 1. Discuss the ways in which cultural differences could potentially cause a barrier in the communication process
Describe exact investigative techniques that you would use : Describe the exact investigative techniques that you would use to analyze the users' information, habits, and history for each program.
What steps of the human resources cycle does company handle : Think about how human resources are handled at the company you work for, or one you have worked for in the past. In the discussion thread.
Discuss common obstacles toward goal attainment : 1. Discuss common obstacles toward goal attainment presented by clients with different presenting problems, personalities or lifestyles.
How can virtualization be used by cloud service providers : Do some Internet research to identify businesses who have suffered because of cloud security weaknesses or failures.
Pick one type of memory impairment to discuss : Describe the symptoms, the mechanisms in the brain that are involved, and most common etiologies - involving the memory impairment you have chosen

Reviews

Write a Review

Computer Engineering Questions & Answers

  Mathematics in computing

Binary search tree, and postorder and preorder traversal Determine the shortest path in Graph

  Ict governance

ICT is defined as the term of Information and communication technologies, it is diverse set of technical tools and resources used by the government agencies to communicate and produce, circulate, store, and manage all information.

  Implementation of memory management

Assignment covers the following eight topics and explore the implementation of memory management, processes and threads.

  Realize business and organizational data storage

Realize business and organizational data storage and fast access times are much more important than they have ever been. Compare and contrast magnetic tapes, magnetic disks, optical discs

  What is the protocol overhead

What are the advantages of using a compiled language over an interpreted one? Under what circumstances would you select to use an interpreted language?

  Implementation of memory management

Paper describes about memory management. How memory is used in executing programs and its critical support for applications.

  Define open and closed loop control systems

Define open and closed loop cotrol systems.Explain difference between time varying and time invariant control system wth suitable example.

  Prepare a proposal to deploy windows server

Prepare a proposal to deploy Windows Server onto an existing network based on the provided scenario.

  Security policy document project

Analyze security requirements and develop a security policy

  Write a procedure that produces independent stack objects

Write a procedure (make-stack) that produces independent stack objects, using a message-passing style, e.g.

  Define a suitable functional unit

Define a suitable functional unit for a comparative study between two different types of paint.

  Calculate yield to maturity and bond prices

Calculate yield to maturity (YTM) and bond prices

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd