From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Digital forensics

Digital forensics

- In this section of the course, we're going to discuss digital forensics and how we can collect evidence and perform some basic analysis on that evidence when an incident or breach occurs. Now, in this section, we're going to be focused on Domain 2 Security Operations, specifically objective 2.8. Objective 2.8 states that you must explain the importance of forensic concepts. Now, as we start out this section, we're going to begin by discussing the digital forensics process and its four steps, including identification, collection, analysis, and reporting or presentation. Then we'll discuss one of the most important concepts in digital forensics, the chain of custody. After that, we'll talk about the order of volatility and why it's important to collect evidence in a specific order to prevent it from being modified before an investigator can actually collect it successfully. Finally, we're going to discuss the concepts of cryptoanalysis and steganalysis, which can be used by…

Contents