You are the lead forensics investigator for xyz inc -- an

Assignment Help Computer Networking
Reference no: EM13387884

You are the lead forensics investigator for XYZ, Inc. -- an industry leading cyber forensic company. You have just been notified that a top 5 health care company (HCC Partners in Life) has hired your company to investigate a potential breach of their medical records system.

The HCC Security Operations Center (SOC) identified some “inconsistencies” in the intrusion detection system (IDS) logs that caused the reliability to be questioned. HCC uses Snort IDS’ running on Linux systems. In addition, the lead HCC database administrator received a strange e-mail from Human Resources (HR), which contained a benefits attachment. When she opened the attachment, the document was blank. She noticed that her system has been acting “strangely” after opening the attachment. She operates a Microsoft Windows XP workstation.

Your team has been tasked with analyzing the HCC network, database server, and any workstations you suspect to determine if there was a breach and any potential patient data leakage. The database server is a Microsoft Windows 2003 Server running Microsoft SQL Server 2008.

If there is any evidence of a breach, HHC has a history of taking these types of incidents to court for prosecution to the full extent of the law.

Note: You are representing the forensic team in this case scenario. The final exam is individual work with no collaboration permitted. 

· Describe your plan for processing the potential crime/incident scene. (30 points). Some of the items you will want to cover include (not all inclusive):

How will your team c?

How will you prepare for the search?

What steps will your team take if you need to seize any digital evidence?

What documentation processes will you follow to help support any potential legal proceedings?

How will your team/company ensure proper storage/chain of evidence processes are followed?

· Discuss how your team will approach and process the database administrator’s computer -- considering the potential malware on her system. (15 points).

Include the steps you will use to image her drive.

The areas on her system you will analyze for potential evidence of infection and/or modification.

Other items.

Discuss how your team will approach and process the database server -- as this is the location for patient medical records. (15 points).

Include the steps you will use to image the server’s hard drive.

The areas on the server’s system you will analyze for potential evidence of infection and/or modification.

Other items.

· Discuss how you prepare your team to be expert witnesses or support any expert testimony court requirements. (15 points).

Include the steps you take in the documentation phases of your investigation.

How you prepare your team for court testimony.

Ethics responsibilities you follow and require in your team’s performance.

Reference no: EM13387884

Questions Cloud

Write an apa style paper outlining the effects of financial : write an apa style paper outlining the effects of financial planning governance and ethical issues in modern economies.
Strayer university all rights reserved this document : copy 2013 strayer university. all rights reserved. this document contains strayer university confidential and
The marginal revenue function is mr250-q graph total : the demand curve is given byqd500-2pxa. what is the total revenue function?b. the marginal revenue function is mr250-q.
Which of following statements regarding depreciation is : which of the following statements about depreciation is correct?a. the depreciation method selected has no impact on
You are the lead forensics investigator for xyz inc -- an : you are the lead forensics investigator for xyz inc. -- an industry leading cyber forensic company. you have just been
Which of the following describes the purpose of : which of the following describes the purpose of depreciation?a.to reflect the change in replacement cost of the
Firm a has 10000 in assets entirely financed with equity : 1. firm a has 10000 in assets entirely financed with equity. firm b also has 10000 in assets but these assets are
What do you believe is the significance of these areas to : what are the major components of a strategic management process? in your view which of these components is the most
Analyze the income statement of eastman kodak write a : each chapter in the textbook contains a continuation of this problem. the objective is to learn how to do a

Reviews

Write a Review

Computer Networking Questions & Answers

  When organizations develop risk management plans they need

when organizations develop risk management plans they need to consider the value of the assets being protected and the

  Advantages and disadvantages of remote access solution

Describe whether or not your network design will support dial-up or VPN remote access by using descriptions of following aspects: advantages and disadvantages of remote access solution.

  Part- aduring the labs we used the national vulnerability

part- aduring the labs we used the national vulnerability database. select a recent vulnerability from that database

  Explain standard analog-to-digital sampling rate

What is the bandwidth required (in bps) if synchronous time division multiplexing is used, along with the standard analog-to-digital sampling rate, and each sample is converted into an 8-bit value?

  Impact of a particular trend in technology

Analyze the impact of a particular trend in technology on education and analyses of various authors on innovations and technological transformations in education and in other fields.

  Describe available bandwidth as a function of n

Assume that N Ethernet stations, all trying to send at same time, need N/2 slot times to sort out who transmits next. Describe available bandwidth as function of N.

  Network ids diagram of lan depiting two new network

Subnet a class C network into subnets using 2 of the resulting new Network IDs Diagram a woring LAN depiting the two newnetworks.

  Find finish actual packet completion-order of transmission

Arrival at time t = 1, length 3; arrival at t = 2, length 1. Buffer 3: arrival at time t = 3, length 5. You need to find out the finish tag, order of transmission and actual packet completion times for each packet arrival.

  Computing depreciation using three-year macrs rates

Depreciation will be calculated using the 3-year MACRS rates of 33%, 45%, 15%, and 7% for the first through the fourth year, respectively. Looner Industries' marginal tax rate is 40%, and its cost of capital is 10%. Should the plant be built?

  You are required to set up a small network with network id

you are required to set up a small network with network id 200.100.50.16027. in this network there are three routers

  Explain the main differences between http version

Explain FTP and TFTP and their main differences. Using a diagram, explain the main differences between HTTP version 1.0 and 1.1

  1 research the types of media that were covered in this

1. research the types of media that were covered in this weeks lectures utp stp fiber optic and wireless and create a

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd