Describe the volatile live acquisition process

Assignment Help Computer Engineering
Reference no: EM132029761

Question: With the identification and preservation of the physical and digital evidence completed the incident response team must now enter the data collection phase. During the data collection phase, the investigative team must collect volatile evidence first, and non-volatile second. Describe the volatile and non-volatile evidence types to be collected and the methods to both collect and analyze the two types of evidence.

• Describe the volatile live acquisition process to collect evidence related to system memory and registry changes and analysis methods conducted over this evidence.

• Describe the non-volatile acquisition process of evidence collection over powered down systems and devices, and the related analysis methods used over non-volatile evidence.

• Describe the exact investigative techniques that you would use to analyze the users' information, habits, and history for each program. Explain the reasons for your selected techniques.

Remember to address forensic evidence you might find relating to the ransomware attack. You should be making references to specific directories, files, file types, registry entries and log files which point to sources of the incident forensic evidence.

The 16-18 slide PowerPoint presentation should include the following:

• Title Slide (1)

• Topics of Discussion Slide (1)

• Windows 10 Operating System (3 slides)

• Registry and Memory (2 slides)

• Internet Explorer (3 slides)

• Outlook e-mail (2 slides)

• Photoshop (2 slides)

• Office (3 slides)

• References Slide (1)

Please add your file.

For assistance with your assignment, please use your text, Web resources, and all course materials.

Reference no: EM132029761

Questions Cloud

Simple and fractional distillations : Why are boiling chips added to the round bottom flasks of both simple and fractional distillations?
Liquid separation than a standard simple distillation : How/why does this allow for a better liquid/liquid separation than a standard simple distillation?
What is the specific heat of helium : It takes 148.8 calories of heat to raise the temperature of the Helium in the balloon to 33.0°C. What is the specific heat of Helium?
What is the monthly payment necessary to amortize this loan : Ron borrows $5,130,329 to purchase a warehouse. What is the monthly payment necessary to amortize this loan?
Describe the volatile live acquisition process : Describe the volatile live acquisition process to collect evidence related to system memory and registry changes and analysis methods conducted.
What is the new temperature of the water after adding : What is the new temperature of the water after adding the heat? Remember that the specific heat of water
Criteria for completing a successful recrystallization : What is the most important criteria for completing a successful recrystallization?
Indicate that the recrystallization was a success : Which of the following would indicate that the recrystallization was a success.? Which solvents would be best suited for recrystallization?
Discuss strengths of memory management techniques : Discuss the strengths and weaknesses of the following memory management techniques: Fixed Partitioning: Main memory is divided into a number of static partition

Reviews

Write a Review

Computer Engineering Questions & Answers

  Taskanswer the question below in an academically rigorous

taskanswer the question below in an academically rigorous manner using business report style with claims supported by

  Discuss the advantages and disadvantages of firewalls

Discuss the advantages and disadvantages of firewalls with iptables and make suggestions to overcome the disadvantages in your report.

  What are the roles stakeholders have within IT projects

Primary Task Response: Within the Discussion Board area, write 400-600 words that respond to the following questions with your thoughts, ideas, and comments.

  Describe two methods for minimizing clustering

Describe two methods for minimizing clustering. Name four advantages of a chained hash table over open addressing.

  Explain the concept of phase shift in oscillators

Explain the concept of phase shift in oscillators and how it is controlled in oscillator circuits.

  Make a heading that contains the name of the software

discuss a specific virus software, its advantages and disadvantages. make a heading that contains the name of the software you are reviewing. It should be about half-page or less.

  Design a class named player that holds a player number

Design a class named Player that holds a player number and name for a sports team participant.

  How deep can the procedure calls go before registers

How deep can the procedure calls go before registers must be saved in memory? (That is, what is the maximum number of "active" procedure calls that can be made before we need to save any registers in memory?)

  Implementing type parameterization in java

Do some investigation and explore whether C# requires that all objects be allocated from the heap and how it approaches type parameterization.

  Question regarding the white rabbit

A magician has a hat that holds two rabbits. One rabbit is black and the other is white. In his last 16 performances he has randomly pulled the black rabbit from the hat 16 times. The probability that he will pull the white rabbit from the hat in ..

  Efficiency and effectiveness of project communications

An effective communication strategy is absolutely essential for achieving effective project integration management. Any time the aim is to integrate numerous concurrently operating activities, the role of communication becomes central. This is as ..

  How many times each smaller fibonacci number will calculated

In the recursive calculation of Fn , determine exactly how many times each smaller Fibonacci number will be calculated.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd