WGU D431BFN1_ BFN1 TASK 1_ INVESTIGATIVE PLAN OF ACTION |
LATEST UPDATE WITH COMPLETE SOLUTIONS
Investigation Analysis Plan
DETAILS OF METHODS USED TO PERFORM EVIDENCE COLLECTION AND ANALYSIS
Ben Brown
STUDENT ID: 001538223
DIGITAL FORENSICS IN CYBERSECURITY - D431
, 1
This document is the plan of action that will be taken as part of an investigation request from a
client’s legal team. The client has reason to believe that an internal employee, one John Smith, has
taken/accessed information that is considered proprietary and confidential. Per the client, Smith, was
not permitted to view or access any confidential or proprietary information. Approval has been given to
proceed with an investigation to determine if in fact Mr. Smith, violated company policy by accessing
and/or sharing proprietary and confidential information. The goal of the investigation is to find, preserve
and prepared the evidence that is gathered, in an attempt to determine if Mr. Smith has in fact violated
company policy. (Easttom, 2022) In this document, we will present how the evidence will be collected
and analyzed. Due to the sensitive nature of the investigation, all results and data collected will be kept
confidential and only shared with client approved parties.
My team and I will arrive at the client’s office after hours, to avoid any unnecessary concern or
confusion amongst the company employees. The first action we will take is to secure the investigation
scene and take photographs and catalog all items that the team will access and/or analyze. We will
document any cables or external devices that are connected to the suspect machine, take pictures of the
machine from all angles, and ensure that all configuration data is documented. We will then proceed to
use task manager to check for any running processes. We will then take a photograph of the screen,
showing the output from task manager. (Easttom, 2022) We will proceed to run the net sessions
command to observe any established network sessions, i.e. other individuals remotely logged in to the
system, and then take a photograph of the output on the screen. (Easttom, 2022) We will then proceed
to run the openfiles command to determine if any shared files and or folders are currently open, and by
which user. We will take another photograph of the output on the screen. (Easttom, 2022)
LATEST UPDATE WITH COMPLETE SOLUTIONS
Investigation Analysis Plan
DETAILS OF METHODS USED TO PERFORM EVIDENCE COLLECTION AND ANALYSIS
Ben Brown
STUDENT ID: 001538223
DIGITAL FORENSICS IN CYBERSECURITY - D431
, 1
This document is the plan of action that will be taken as part of an investigation request from a
client’s legal team. The client has reason to believe that an internal employee, one John Smith, has
taken/accessed information that is considered proprietary and confidential. Per the client, Smith, was
not permitted to view or access any confidential or proprietary information. Approval has been given to
proceed with an investigation to determine if in fact Mr. Smith, violated company policy by accessing
and/or sharing proprietary and confidential information. The goal of the investigation is to find, preserve
and prepared the evidence that is gathered, in an attempt to determine if Mr. Smith has in fact violated
company policy. (Easttom, 2022) In this document, we will present how the evidence will be collected
and analyzed. Due to the sensitive nature of the investigation, all results and data collected will be kept
confidential and only shared with client approved parties.
My team and I will arrive at the client’s office after hours, to avoid any unnecessary concern or
confusion amongst the company employees. The first action we will take is to secure the investigation
scene and take photographs and catalog all items that the team will access and/or analyze. We will
document any cables or external devices that are connected to the suspect machine, take pictures of the
machine from all angles, and ensure that all configuration data is documented. We will then proceed to
use task manager to check for any running processes. We will then take a photograph of the screen,
showing the output from task manager. (Easttom, 2022) We will proceed to run the net sessions
command to observe any established network sessions, i.e. other individuals remotely logged in to the
system, and then take a photograph of the output on the screen. (Easttom, 2022) We will then proceed
to run the openfiles command to determine if any shared files and or folders are currently open, and by
which user. We will take another photograph of the output on the screen. (Easttom, 2022)