Computer security incident

Assignment Help Computer Network Security
Reference no: EM133319

QUESTION 1

(a)Briefly explain how the suspect Dobson in Utah has been intercepting his ex-employer email.

(b)According to the U.S. Department of justice, computers play three distinct roles in a criminal case. Momentarily portray the three roles. Give an instance in each case.

(c)Briefly depict the three types of data that a forensic examiner has to work with. Which one of the three is more tricky to obtain and why?

(d)Judge the following case:

It is supposed that two employees, who had their contract terminated from a Brokering and Insurance company, have been attempting to steal the accounts of some of the consumers shortly before leaving the company.
As a forensic examiner, what type of evidence can be gathered from the palm pilots of these ex-employees to be able to help find which customers they have been targeting?

QUESTION 2

(a)Describe "computer security incident". Which kind of security incident needs to be switched immediately? Give an instance of such a type of incident.

(b)File five devices from which electronic evidence can be obtained.

c) Presume that you are a forensic expert and that you have been called upon a crime scene. Presume the crime scene spans across an office room.

(i) Elucidate two ways in which you will document the electronic crime scene before you start seizing evidence.

(ii) What type of packaging would be best to hold the internal hard drive retrieved from a suspect computer?

(iii) Briefly explain the different information required in an exhibit label or tag.

QUESTION 3

(a)give explanation for the "Locard's Exchange Principle" and its implications in the context of computer forensics. Give two instances to support your answer.

(b)Which command line interface tools or commands can be used to find the subsequent below?

(i) Logged-on users

(ii) username used to access the system via a remote login session

(iii) files open on system via remote connection

(iv) basic information about running processes on a system

(v) modules or DLLs a process is using

(c)You are contracted to work as a computer forensics investigator for a regional bank that has four 30 TB server that store customer data. Describe the method that would be the most efficient to acquire digital evidence from the servers. Give good reason for your answer.

QUESTION 4

(a)"Live data capture is even more important in the case of router forensics". Give good reason this statement.

(b)Briefly describe the different memory components of a typical router.

(c)Detail two commands that can be used to gather the following type of volatile evidence from a router:

(i) Configuration and user

(ii) Local logs process and memory

(iii) Network Information

(iii) File system

(d)(i) Portray the NTP vulnerability of some Cisco IOS routers.

(ii) What is the impact of this attack?

Reference no: EM133319

Which four security controls would be your first priority

Suppose you started working as a network manager at a medium-sized firm with an Internet presence, and discovered that the previous network manager had done a terrible job o

Describe common concepts in information security

Describe common concepts in information security, privacy and the law. You will learn how to present and justify risk analysis for assets in an organizational setting and wi

Describes the five phases of an attack

CSIS 343- Our text describes the five phases of an attack, and we'll be discussing all those phases in this course. Although the phases from the text represent a generalized

Description of des encryption feistel structure algorithm

Prove that y’ = c(y) (i.e., if we complement the plaintext and the key, then the ciphertext is also complemented). [This is Question 3.3 of the textbook. Hint: this can be pro

Combine the two disks into one logical volume

Illustrate your explanation by using the Linux Log- ical Volume Manager to combine the two spare disks available on the Virtual Debian distribution. Combine the two disks in

Program to strip all occurrences

Write a program to strip all occurrences of these characters: '(', ')' and '-'. Also, strip all the leading and trailing whitespace characters. Display the stripped phone nu

Objects-attributes and methods of the o-o model

Briefly explain what are objects, attributes, and methods of the O-O model. Draw an object model(s) and list a minimum of five attributes and five methods for the class and s

Examine the contents of the security and privacy tabs

Using a Microsoft Windows XP, Vista, or 7, open Internet Explorer. Click Internet Options on the Tools menu. Examine the contents of the Security and Privacy tabs. How can t

Reviews

Write a Review

 
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd