Chapter 18

Utilizing Basic Digital Forensics Techniques

This chapter covers the following topics related to Objective 4.4 (Given a scenario, utilize basic digital forensics techniques) of the CompTIA Cybersecurity Analyst (CySA+) CS0-002 certification exam:

  • Network: Covers network protocol analyzing tools including Wireshark and tcpdump.

  • Endpoint: Discusses disk and memory digital forensics.

  • Mobile: Covers mobile forensics techniques.

  • Cloud: Includes forensic techniques in the cloud.

  • Virtualization: Covers issues and forensics unique to virtualization.

  • Legal hold: Describes the legal concept of retaining information for legal purposes.

  • Procedures: Covers forensic procedures.

  • Hashing: Describes forensic verification, including changes to binaries. ...

Get CompTIA Cybersecurity Analyst (CySA+) CS0-002 Cert Guide, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.