Chapter 30
Digital Forensics
This chapter covers the following official Security+ exam objective:
▶ 4.5 Explain the key aspects of digital forensics.
Essential Terms and Components
Forensics is the process of preserving evidence and collecting data. During the process, the following actions should be performed:
▶ Document an investigation from initial notification through conclusion.
▶ Locate data and any devices of potential evidentiary value.
▶ Identify data of interest.
▶ Establish an order of volatility to identify the first level of data capture desired.
▶ Eliminate external ...
Get CompTIA Security+ SY0-601 Exam Cram, 6th Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.