Logo
Question DetailsNormal
$ 65.00
CSEC650 Final Exam | Complete Solution
Question posted by
request

Final Exam Guidelines

CSEC650 Final Exam 

Due Date/Time: 11:59 PM EDT August 6, 2015. Late submissions cannot be accepted, due to end of semester.   

This final examination is worth 20 percent of your total grade. There are four (4) questions and the maximum point values are included with each question.

The recommended length for the final exam is 10 - 15 doubled spaced pages excluding diagrams, illustrations or other addendum. The use of APA formatting is required for any in-text citations and reference list. Please submit ONE document for all answers in Word or PDF in the Final Exam assignment folder in LEO by the due date. Each response is to immediately follow the question as follows:

 

1.     Tasking A -- approximately 600 - 1000 words (2 - 4 pages) excluding diagrams, illustrations or other addendum.

 

2.     Tasking B -- approximately 600 - 800 words (2 - 3 pages) excluding diagrams, illustrations or other addendum.
 

3.     Tasking C -- approximately 600 - 800 words (2 - 3 pages) excluding diagrams, illustrations or other addendum.
 

4.     Tasking D -- approximately 600 - 800 words (2 - 3 pages) excluding diagrams, illustrations or other addendum.

________________________________________________________________


The final exam must include this sheet with the student's name and the date as well as the following statement:

 

Honor Pledge
This exam is my own work. I received no assistance from any other individual, commercial entity, or unauthorized source.

Suspected violations of the academic integrity policy of the University of Maryland University College will be processed in accordance to the Procedures for Handling Charges of Alleged Academic Dishonesty outlined in Policy 150.25 - Academic Dishonesty and Plagiarism (https://www.umuc.edu/policies/academicpolicies/aa15025.cfm). 

In typing my name following the word 'Signature', I intend that this certification will have the same authority and authenticity as a document executed with my hand-written signature.


Signature: [Insert your name here]

Date: [Insert date here]
 

________________________________________________________________

Final Exam Scenario


You are the lead forensics investigator for XYZ, Inc. -- an industry leading cyber forensic company. You have just been notified that a top 5 health care company (HCC Partners in Life) has hired your company to investigate a potential breach of their medical records system.

 

The HCC Security Operations Center (SOC) identified some “inconsistencies” in the intrusion detection system (IDS) logs that caused the reliability to be questioned. HCC uses Snort IDS’ running on Linux systems. In addition, the lead HCC database administrator received a strange e-mail from Human Resources (HR), which contained a benefits attachment. When she opened the attachment, the document was blank. She noticed that her system has been acting “strangely” after opening the attachment. She operates a Microsoft Windows XP workstation.

 

Your team has been tasked with analyzing the HCC network, database server, and any workstations you suspect to determine if there was a breach and any potential patient data leakage. The database server is a Microsoft Windows 2003 Server running Microsoft SQL Server 2008.

If there is any evidence of a breach, HHC has a history of taking these types of incidents to court for prosecution to the full extent of the law.


Note: You are representing the forensic team in this case scenario. The final exam is individual work with no collaboration permitted. 
________________________________________________________________

Your Tasking

 

A.    Describe your plan for processing the potential crime/incident scene. (30 points). Some of the items you will want to cover include (not all inclusive):

    1. How will your team identify potential digital evidence?
    2. How will you prepare for the search?
    3. What steps will your team take if you need to seize any digital evidence?
    4. What documentation processes will you follow to help support any potential legal proceedings?
    5. How will your team/company ensure proper storage/chain of evidence processes are followed?

 

B.    Discuss how your team will approach and process the database administrator’s computer -- considering the potential malware on her system. (15 points).

    1. Include the steps you will use to image her drive.
    2. The areas on her system you will analyze for potential evidence of infection and/or modification.
    3. Other items.

 

C.    Discuss how your team will approach and process the database server -- as this is the location for patient medical records. (15 points).

 

1.     Include the steps you will use to image the server’s hard drive.

2.     The areas on the server’s system you will analyze for potential evidence of infection and/or modification.

3.     Other items.

D.    Discuss how you prepare your team to be expert witnesses or support any expert testimony court requirements. (15 points).

    • Ethics responsibilities you follow and require in your team’s performance.
    1. Include the steps you take in the documentation phases of your investigation.
    2. How you prepare your team for court testimony

Please note total grade points are 100%, 75 of which are for the 4 questions.

The other 25% is for 

Quality of documented support (10%)

Organization (5%)

Writing style (5%)

Use of proper APA formatting (5%)

Available Solution
$ 65.00
CSEC650 Final Exam | Complete Solution
  • This Solution has been Purchased 17 time
  • Submitted On 04 Aug, 2015 12:50:44
Solution posted by
solution
Computer technology is the significant basic piece of ordinary human life, and it is becoming quickly, as are PC unlawful acts, for example, financial extortion, unauthorized interruption, data fraud and intellectual theft...
Buy now to view full solution.
closebutton

$ 629.35