Task 2 |Passed on First Attempt |Latest Update with
Complete Solution
: Forensic Investigation
Amanuel Girma
D431: Digital Forensics in Cybersecurity
A1: STEPS USED TO CREATE FORENSICS CASE FILE
To begin the forensic examination, I launched the Autopsy application in the
virtual lab environment. From the main interface, I selected "Create New
Case," which initiated the case creation wizard. I then entered the required
information, including a unique case name and designated directory path
where the case files would be stored.
On the next screen, I input the case number, assigned examiner name, and
any additional identifiers, then clicked "Finish."
, The system generated the case folder and prepared the Autopsy
environment for evidence ingestion.
A2: STEPS USED TO IDENTIFY POTENTIAL EVIDENCE
Following case setup, I proceeded to add the data source. I clicked "Add
Data Source" and chose "Disk Image or VM File." I then navigated to the
location of the disk image file labeled JSmith_Q1.001 and selected it for
analysis.