assignment 2

2
Computer Forensics (CNET239) Assignment#2- 60 points Objective: In this assignment, we will handle a computer forensic case working as an investigator in a large corporation’s IT security department. Your duties include conducting internal computing investigations and forensics examinations on company computing systems. A paralegal from the Law Department asks you to examine a USB drive belonging to an employee who left the company and now works for a competitor. The Law Department is concerned that the former employee might possess sensitive company data. They want to know whether the USB drive contains anything significant. - The USB drive is already examined and an image is taken. - Based on an initial assessment of examination objectives, some important keywords of interest are identified. They are: Antonio, Hugh Evans and Horatio. You need to draw a detailed plan for your investigation. Use the guidelines provided in the lectures. Then follow on with the examinations and report your findings. Follow the documentation guidelines and use lessons learned through the templates you analyzed in the previous assignments. Take the following actions: A. Prepare a detailed plan for your investigation (10 points). B. Examine the image file and choose a right tool to open and carry out the examinations. Search for the keywords and take screenshots (10 points). C. Examine any files of interest and report on your findings (20 points).

Upload: joshua-hicks

Post on 22-Nov-2015

4 views

Category:

Documents


0 download

DESCRIPTION

Assignment 2

TRANSCRIPT

Computer Forensics (CNET239)Assignment#2- 60 points

Objective: In this assignment, we will handle a computer forensic case working as an investigator in a large corporations IT security department. Your duties include conducting internal computing investigations and forensics examinations on company computing systems. A paralegal from the Law Department asks you to examine a USB drive belonging to an employee who left the company and now works for a competitor. The Law Department is concerned that the former employee might possess sensitive company data. They want to know whether the USB drive contains anything significant. The USB drive is already examined and an image is taken. Based on an initial assessment of examination objectives, some important keywords of interest are identified. They are: Antonio, Hugh Evans and Horatio. You need to draw a detailed plan for your investigation. Use the guidelines provided in the lectures. Then follow on with the examinations and report your findings. Follow the documentation guidelines and use lessons learned through the templates you analyzed in the previous assignments. Take the following actions:A. Prepare a detailed plan for your investigation (10 points).B. Examine the image file and choose a right tool to open and carry out the examinations. Search for the keywords and take screenshots (10 points). C. Examine any files of interest and report on your findings (20 points). D. Keep a detailed journal of your activities (10 points). Make sure the dates are recorded. E. Prepare a report including the above with proper structure similar to sample reports that you have already studied (10 points).