Digital investigation, computer science homework help

User Generated

nyrk3191

Computer Science

Description

LMJ-Ad management has done some research about the legal recourse that is available to them, and they heard that your team will create copies of hard drives and perform analysis of the copies and not the originals.

  • Describe the processes of Chain of custody, and describe how a Write blocker is used as a mechanism to preserve the original copy of the digital media.
  • Take this opportunity to describe why analysis against an image copy is desirable.
  • Describe how to generate a forensic disk image (or bit-for-bit disk copy of all sectors on the media) and how file verification can ensure that the image copy is the same as the original.

User generated content is uploaded by users for the purposes of learning and should be used following Studypool's honor code & terms of service.

Explanation & Answer

Here you go buddy.

Digital investigation – procedures outline
I.
II.
III.
IV.
V.

Processes of Chain of custody
How a Write blocker is used as a mechanism to preserve the original copy of the digital
media.
Why analysis against an image copy is desirable.
How to generate a forensic disk image (or bit-for-bit disk copy of all sectors on the
media)
How file verification can ensure that the image copy is the same as the original.


Surname 1

Surname
Course Name
Professor’s name
University affiliation
Date
Digital investigation
Chain of Custody legally refers to the sequential documentation reflecting the custody
control, analysis and deposition of the physical or electronic evidence. Chain of custody simply
documents how evidence is handled in the aspect of digital investigation (Quirchmayer 596). The
written document describes how investigation process was gathered, analyzed and kept to be
used in the court of law. Therefore, for any unit of physical evidence taken by an investigator,
there must be a sequence of a chain of custody report maintained.
Chain of Custody has its main aims which include ensuring that the sample that is
collected is similar to the one that is being analyzed. Secondly, it ensures stat the sample is not
by any chance compromised or tampered with between the process of collection, examination,
and testing. Digital evidence preservation is of importance inclusive of the chain of custody and
should be...


Anonymous
Just what I needed. Studypool is a lifesaver!

Studypool
4.7
Trustpilot
4.5
Sitejabber
4.4

Similar Content

Related Tags