QuestionQ22
Threat Intelligence in Incident ResponseSam, a digital forensic expert, is handling a file-tampering case involving a system in an organization’s administrative department. To analyze the acquired data and draw conclusions about the case, Sam performs these steps:
- Analyze file content for data usage.
- Analyze the date and time of file creation and modification.
- Identify the users associated with file creation, access, and modification.
- Determine the file’s physical storage location.
- Generate a timeline.
- Identify the root cause of the incident.
Identify the type of analysis Sam performed in this scenario.
- A Reporting
- B Data analysis
- C Case analysis
- D Search and seizure
Community Discussion