WGU C840 Task 1 Forensic Investigation STUDY GUIDE 2023 RATED A+.
WGU C840 Task 1 Forensic Investigation STUDY GUIDE 2023 RATED A+. A1. The investigative team will schedule a meeting or meetings with the oil company’s HR, Legal and senior management team to discuss the issues. At that time the team will review the requirements to ensure that it is meeting the business needs of the Legal team and senior management. The investigative team will be briefed on the issue and will be made aware that they are investigating John Smith for allegedly stealing proprietary company information that is in direct violation of the signed non-disclosure agreement and acceptable use policy. After the initial meetings have been held and the scope of the work has been identified the investigative team will secure the scene where the computer of John Smith is located. They will do this in a manner consistent with proper forensic investigation. At this time a chain of custody will be started to document evidence that is found. The team will work with the IT department of the oil company to gain access to server logs as a step in determining what data and devices have been accessed. The team will capture all volatile memory on the workstations used by John Smith and create a disk image or images that will have hash values calculated to ensure the integrity of the data and evidence is maintained. The team will be using MAGNET RAM to capture the physical memory of the running pc, this will include running processes and programs. The team will also be using FTK Imager to create the images of the hard drives that were used by John Smith. During the imaging process FTK Imager will calculate the MD5 and SHA1 hash. The team will also be using Wireshark to see if there are any connections to the suspect pc that might need to be investigated further. At this point the team can shut down the pc and move it to a secure location to continue the investigation. The above plan will be followed to minimize the amount of downtime caused for the company and the users in the surrounding areas. A2. Now that the computers have been thoroughly documented in the field and moved to a secure location the investigators can continue their more in-depth analysis. When the investigators are collecting evidence, they will be required to photograph the workstation setups as well as what is showing on the screens when they arrive to investigate. The team can now use the images created by FTK Imager and MAGNET RAM to further investigate for signs of data and information being used in a manner not consistent with the company’s policies. The team will be able to do keyword searches looking for proprietary information. They will also be looking for data concealed in other files using s
Información del documento
- Subido en
- 16 de junio de 2023
- Número de páginas
- 3
- Escrito en
- 2022/2023
- Tipo
- Examen
- Contiene
- Preguntas y respuestas