QuestionQ22

Threat Intelligence in Incident Response

Sam, a digital forensic expert, is handling a file-tampering case involving a system in an organization’s administrative department. To analyze the acquired data and draw conclusions about the case, Sam performs these steps:

  1. Analyze file content for data usage.
  2. Analyze the date and time of file creation and modification.
  3. Identify the users associated with file creation, access, and modification.
  4. Determine the file’s physical storage location.
  5. Generate a timeline.
  6. Identify the root cause of the incident.

Identify the type of analysis Sam performed in this scenario.

  • A Reporting
  • B Data analysis
  • C Case analysis
  • D Search and seizure
Explanation

Data analysis in digital forensics examines acquired evidence to isolate useful information. It includes analyzing file contents and metadata, identifying users connected to file activity, determining physical file locations, producing timelines, and identifying an incident’s root cause.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!