Computer security incident

Assignment Help Computer Network Security
Reference no: EM133319

QUESTION 1

(a)Briefly explain how the suspect Dobson in Utah has been intercepting his ex-employer email.

(b)According to the U.S. Department of justice, computers play three distinct roles in a criminal case. Momentarily portray the three roles. Give an instance in each case.

(c)Briefly depict the three types of data that a forensic examiner has to work with. Which one of the three is more tricky to obtain and why?

(d)Judge the following case:

It is supposed that two employees, who had their contract terminated from a Brokering and Insurance company, have been attempting to steal the accounts of some of the consumers shortly before leaving the company.
As a forensic examiner, what type of evidence can be gathered from the palm pilots of these ex-employees to be able to help find which customers they have been targeting?

QUESTION 2

(a)Describe "computer security incident". Which kind of security incident needs to be switched immediately? Give an instance of such a type of incident.

(b)File five devices from which electronic evidence can be obtained.

c) Presume that you are a forensic expert and that you have been called upon a crime scene. Presume the crime scene spans across an office room.

(i) Elucidate two ways in which you will document the electronic crime scene before you start seizing evidence.

(ii) What type of packaging would be best to hold the internal hard drive retrieved from a suspect computer?

(iii) Briefly explain the different information required in an exhibit label or tag.

QUESTION 3

(a)give explanation for the "Locard's Exchange Principle" and its implications in the context of computer forensics. Give two instances to support your answer.

(b)Which command line interface tools or commands can be used to find the subsequent below?

(i) Logged-on users

(ii) username used to access the system via a remote login session

(iii) files open on system via remote connection

(iv) basic information about running processes on a system

(v) modules or DLLs a process is using

(c)You are contracted to work as a computer forensics investigator for a regional bank that has four 30 TB server that store customer data. Describe the method that would be the most efficient to acquire digital evidence from the servers. Give good reason for your answer.

QUESTION 4

(a)"Live data capture is even more important in the case of router forensics". Give good reason this statement.

(b)Briefly describe the different memory components of a typical router.

(c)Detail two commands that can be used to gather the following type of volatile evidence from a router:

(i) Configuration and user

(ii) Local logs process and memory

(iii) Network Information

(iii) File system

(d)(i) Portray the NTP vulnerability of some Cisco IOS routers.

(ii) What is the impact of this attack?

Reference no: EM133319

Questions Cloud

Symmetric encryption algorithms : block cipher and a stream cipher, Caesar cipher, cryptanalytic attacks, mono alphabetic cipher and a poly alphabetic cipher, Mix Columns, Add Round key, PGP services, traffic padding, contrast link and end-to-end encryption
Discretionary and mandatory access control : Logic bombs, War dialing, Ping of death attack, steganography, RSA scheme, digital signature, A chain of certificates, A certificate revocation list, A trust anchor, asymmetric algorithm used by PGP, IPSec mode, IP virtual Private Networks
Network security : SLE, ARO, and ALE, behavioural biometric technology, Enterprise Information Security Policy, Issue Specific Security Policy, System Specific Security Policy, firewalls protect network, creating a DMZ during firewall implementation, use of SSL to se..
Digital forensic investigation : computer security incident, Trojan Defence, anti-forensics technique, chain of custody, FAT file system, SQLOracleHacks.txt, SQLOracleAttacks.txt, SQLInjection.html
Computer security incident : Locard's Exchange Principle, electronic crime scene, modules or DLLs a process, router forensics, Configuration and user, Local logs process and memory, Network Information, File system, Portray the NTP vulnerability of some Cisco IOS routers
Security vulnerabilities of vc : single access point (AP), wireless network, CSMA/CA, goals of information security, Wireless LANs, wireless hacking process, Wired Equivalent Privacy (WEP), Open System Authentication and Shared Key Authentication, Initialisation Vector (IV), RADIU..
Owasp top 10 web application security risks : Reflected XSS and Stored XSS attack, threat Modeling methodologies, Extended Stack Pointer (ESP) and the Extended Base Pointer (EBP), Canary-based defense to buffer overflow attacks in C language, admin.aspx, Index hijacking, cross-site request fo..
Cryptosystem : Block cipher, Primitive root, Confusion, Diffusion, Digital signature, Conventional Symmetric-Key Encryption

Reviews

Write a Review

Computer Network Security Questions & Answers

  Cryptosystem

Block cipher, Primitive root, Confusion, Diffusion, Digital signature, Conventional Symmetric-Key Encryption

  Discuss two drawbacks of steganography

Discuss two drawbacks of steganography Describe the operation of a Trojan Horse program. How can we protect our computer from such a program

  Computer networks and security against hackers

This case study about a company named Magna International, a Canada based global supplier of automotive components, modules and systems. Along with the company analysis have been made in this assignment.

  Modern symmetric encryption schemes

Pseudo-random generators, pseudo-random functions and pseudo-random permutations

  A comprehensive study about web-based email implementation

Conduct a comprehensive study about web-based email implementation in gmail. Optionally, you may use sniffer like wireshark or your choice to analyze the communication traffic.

  Express the shannon-hartley capacity theorem

Express the Shannon-Hartley capacity theorem in terms of where is the Energy/bit and is the psd of white noise.

  Phising email

Phising email It is multipart, what are the two parts? The HTML part, is it inviting the recepient to click somewhere? What is the email proporting to do when the link is clicked?

  Analyse security procedures

Analyse security procedures

  Dos and ddos attack

Denial of Service attack (DoS) and Distributed Denial of service (DDoS) attack, two-factor authentication system, password ageing, biometric devic,  cryptographic attack made Double DES (2DES), Demilitarized Zone (DMZ), SSL protocols

  Scenario-based project

Authentic Assessment:   The scenario will be a realistic, enterprise-level situation encompassing diverse networking components, including Microsoft Windows, Linux, VoIP, security, wireless, and Cisco technologies.

  Question on security infrastructure and protocols

Question on Security infrastructure and protocols

  An overview of wireless lan security - term paper

Computer Science or Information Technology deals with Wireless LAN Security. Wireless LAN Security is gaining importance in the recent times. This report talks about how vulnerable are wireless LAN networks without any security measures and also talk..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd