Blog

Coursehelp
April 16, 2019
QUESTION : No Comments

(Solved) : Work Ccl Group Forensic Investigator Asked Contact Local Company Suspect Employee Breachin Q26203623 . . .

You work for CCL Group as a forensic investigator and have beenasked to contact a local company who suspect an employee ofbreaching company policies. You visit the company and meet with thesystem administrator and manager who explain that an employeeappears to have used a P2P program to download full length moviesonto their work computer. It is thought that they have alsodownloaded a Trojan virus which has resulted in not only theemployee’s computer system failing to boot, but also caused issueswith the entire network.
The employee has been suspended pending the investigation and youwill be provided with full access to the computer system andnetwork. The system administrator and manager have confirmed thatthe employee’s computer system has been left ‘in situ’ and nottampered with, but that the network issue had to be resolved due tothe business needing to function as normal.
You are required to plan and carry out an investigation of theemployee’s computer system and present your findings as a reportfor the system administrator and manager. You have a timescale oftwo weeks to plan and conduct your investigation, completing allrelevant documentation as well as preparing the final report.

Tasks 1 You are required to produce a documented plan of how youare going to approach your computer forensic investigation, whichwill be approved by your supervisor. The plan must include thefollowing:

A documented plan for the computer forensic investigation of theemployee’s system to include: a An annotated diagram of theevidence lifecycle b An explanation of the admissibility ofevidence providing four examples of good practice c Identificationof the types of evidence that could be gathered for thisinvestigation including a justification of the types of evidence tobe collected d Explanation of the precautions that will be taken topreserve the state of each type of evidence e Identification of thehardware and software tools that will be selected to analyse theevidence with a justification of the tools selected f Explanationof the importance of the chain of custody process g Explanation ofthe evidence handling procedures that will be used. 2 After yoursupervisor approves your plan, you can now carry out your computerforensic investigation of the employee’s computer system. Ensurethat you document the investigation process thoroughly to include:a date and time of action b activity type c personnelcollecting/accessing evidence d computer description information edisk drive descriptive information f handling procedure g completedescription of action: • procedure followed • tools used •step-by-step description of analysis and results h reasons foraction taken i notes j collection of evidence k review of evidencel analysis and interpretation of evidence m documentation ofevidence (printouts, photographs etc) and Chain of Custodyrecord.

Expert Answer


. . .

OR
OR

Have a Comment on this Question?

Questions viewed by other students


  • QUESTION : (Solved) : Would Like Help Getting Code Question C Benchmarsk Sorting Methods Listed Using Visual St Q29139380 . . .

    I would like some help getting the code for the question belowin C++.

    Benchmarsk each of the sorting methods listed below using visualstudio.

    Insertion Sort, Bubble Sort Heap Sort. Quick Sort. MergeSort.

    Benchmark each of the above sorting methods for data sizes of10000, 20000, 30000, 40000 and 50000. Display the results in atable as shown below. The table should have rows and columns.However, the rows and columns need not be separated by lines.
      

    Data Size

    Heap Sort Time In Seconds

    Merge Sort Time In Seconds

    Quick Sort Time In Seconds

    Quadratic Sort Time In Seconds

    100000

    200000

    300000

    400000

    500000

    Notes:

    ? Do not use a local array for keeping data values. Use a globalarray for this purpose. You can use dynamically allocated arrays ifyou wish.

    Generate the data using a random generator and store it in aglobal array for use in sorting. If you use a local array of largesize, you will run out of stack space.

    ? Calculate the time taken by a sort routine in seconds asbelow:

    #include

    clock_t start, finish;
    start =clock( ); //time in milliseconds
    sort( );
    finish=clock( ); //time in milliseconds
    //the constant CLOCKS_PER_SEC below is equal to 1000
    double duration = (double) ( (finish-start)/CLOCKS_PER_SEC );//time in secs.

    Expert Answer


    . . .


    view full answer
  • QUESTION : (Solved) : Write Arm Assembly Language Routine Count Number 1s 32 Bit Word R0 Return Result R1 Code F Q34564596 . . .

    Write an ARM assembly language routine to count the number of 1sin a 32‐bit word in r0 and return the result in r1.

    code:

    LDR r0, 0x11AB003F dummy value for rl (11 ones) MOV r1,#0x0 MOV r2,#32 MOVS r0,r0, ROR #1 ADDCS r1,r1,#1 SUBS r2 , r2 , #1 BNE OnesCount ; clear ones counter ;use r2 as the loop counter i Repeat: rotate ro right set Ilags ;if carry set increment 1s counter ; decrement loop counter until all bits tested OnesCount If this was a subroutine Count, the code might be area test, cODE, readwrite ADR sp, Stackl LDR r2 , =0xFFFFFFFF STR r2, [sp] LDR r0, - 0xFFAB123A BL MOV r3,rl NOP NOP ;set up dummy r2 ; dummy data :call routine ; read result Count STMFD sp!, (r2,lr] MOV r1, #0x0 MOV r2,#4 Count ; save r2 and return on the stack onesCount MOVS r0,r0, ROR #1 ADDCS r1,r1,#1 SUBS r2 , r2 , #1 BNE OnesCount LDMFD sp!, (r2,pc) ; restore r2 and returr Stack Stackl DCD 0,0,0,0,0 DCD 0,0,0,0,0

    The following image is a screendump after executing the abovecode. Register r3 contains 0x13 which is 19, the
    number of 1s in 0x11AB003F.

    CAUsers AlanCore7 Desktop ForBrusselsMay2012Chap3Problems.uvproj - pVision4 File Edit iew Project Flash Debug Peripherals Tools SVCS Window Help Registers 3Chap3Problems.asm area test, CoDE, readwrite ADR p, Stackl LDR r2,=0xEEEEEEEE STR r2, [ap] LDR ro, - 0XEEAB123A ;dummy data BL Count MOV 3,rl B Parkilere RegisterValue0 Current OF FAB123A 0x00000013 :set up dumay x2 R1 000000013 call routine : read result endless loop R4 R5 R6 R7 R8 R9 R10 R11 R12 R13 (5P) 0x00000054 R14 (LR) 000000014 R15 (PC) 000000018 0 ParkHere NOP 0 count STMED sp!, 2,1x) MOV Nov saver and return on the stacik r1, #0x0 r2, #32 13 onescount Movs ro,r0 , ROR #1 ADDcs r1,r1, #1 SUBS r2, r2, 1 BNE Onescount 15 restore r2 and return Stack DCD o,o, o, 0,0 User/System Fast Interrupt Interrupt 20 Stack DCD 0,0,0,0,0 21 END Project E Registers Simulation

    LDR r0, 0x11AB003F dummy value for rl (11 ones) MOV r1,#0x0 MOV r2,#32 MOVS r0,r0, ROR #1 ADDCS r1,r1,#1 SUBS r2 , r2 , #1 BNE OnesCount ; clear ones counter ;use r2 as the loop counter i Repeat: rotate ro right set Ilags ;if carry set increment 1s counter ; decrement loop counter until all bits tested OnesCount If this was a subroutine Count, the code might be area test, cODE, readwrite ADR sp, Stackl LDR r2 , =0xFFFFFFFF STR r2, [sp] LDR r0, – 0xFFAB123A BL MOV r3,rl NOP NOP ;set up dummy r2 ; dummy data :call routine ; read result Count STMFD sp!, (r2,lr] MOV r1, #0x0 MOV r2,#4 Count ; save r2 and return on the stack onesCount MOVS r0,r0, ROR #1 ADDCS r1,r1,#1 SUBS r2 , r2 , #1 BNE OnesCount LDMFD sp!, (r2,pc) ; restore r2 and returr Stack Stackl DCD 0,0,0,0,0 DCD 0,0,0,0,0 CAUsers AlanCore7 Desktop ForBrusselsMay2012Chap3Problems.uvproj – pVision4 File Edit iew Project Flash Debug Peripherals Tools SVCS Window Help Registers 3Chap3Problems.asm area test, CoDE, readwrite ADR p, Stackl LDR r2,=0xEEEEEEEE STR r2, [ap] LDR ro, – 0XEEAB123A ;dummy data BL Count MOV 3,rl B Parkilere RegisterValue0 Current OF FAB123A 0x00000013 :set up dumay x2 R1 000000013 call routine : read result endless loop R4 R5 R6 R7 R8 R9 R10 R11 R12 R13 (5P) 0x00000054 R14 (LR) 000000014 R15 (PC) 000000018 0 ParkHere NOP 0 count STMED sp!, 2,1x) MOV Nov saver and return on the stacik r1, #0x0 r2, #32 13 onescount Movs ro,r0 , ROR #1 ADDcs r1,r1, #1 SUBS r2, r2, 1 BNE Onescount 15 restore r2 and return Stack DCD o,o, o, 0,0 User/System Fast Interrupt Interrupt 20 Stack DCD 0,0,0,0,0 21 END Project E Registers Simulation Show transcribed image text LDR r0, 0x11AB003F dummy value for rl (11 ones) MOV r1,#0x0 MOV r2,#32 MOVS r0,r0, ROR #1 ADDCS r1,r1,#1 SUBS r2 , r2 , #1 BNE OnesCount ; clear ones counter ;use r2 as the loop counter i Repeat: rotate ro right set Ilags ;if carry set increment 1s counter ; decrement loop counter until all bits tested OnesCount If this was a subroutine Count, the code might be area test, cODE, readwrite ADR sp, Stackl LDR r2 , =0xFFFFFFFF STR r2, [sp] LDR r0, – 0xFFAB123A BL MOV r3,rl NOP NOP ;set up dummy r2 ; dummy data :call routine ; read result Count STMFD sp!, (r2,lr] MOV r1, #0x0 MOV r2,#4 Count ; save r2 and return on the stack onesCount MOVS r0,r0, ROR #1 ADDCS r1,r1,#1 SUBS r2 , r2 , #1 BNE OnesCount LDMFD sp!, (r2,pc) ; restore r2 and returr Stack Stackl DCD 0,0,0,0,0 DCD 0,0,0,0,0
    CAUsers AlanCore7 Desktop ForBrusselsMay2012Chap3Problems.uvproj – pVision4 File Edit iew Project Flash Debug Peripherals Tools SVCS Window Help Registers 3Chap3Problems.asm area test, CoDE, readwrite ADR p, Stackl LDR r2,=0xEEEEEEEE STR r2, [ap] LDR ro, – 0XEEAB123A ;dummy data BL Count MOV 3,rl B Parkilere RegisterValue0 Current OF FAB123A 0x00000013 :set up dumay x2 R1 000000013 call routine : read result endless loop R4 R5 R6 R7 R8 R9 R10 R11 R12 R13 (5P) 0x00000054 R14 (LR) 000000014 R15 (PC) 000000018 0 ParkHere NOP 0 count STMED sp!, 2,1x) MOV Nov saver and return on the stacik r1, #0x0 r2, #32 13 onescount Movs ro,r0 , ROR #1 ADDcs r1,r1, #1 SUBS r2, r2, 1 BNE Onescount 15 restore r2 and return Stack DCD o,o, o, 0,0 User/System Fast Interrupt Interrupt 20 Stack DCD 0,0,0,0,0 21 END Project E Registers Simulation

    Expert Answer


    . . .


    view full answer
  • QUESTION : (Solved) : Write Arm Program Armsim Following Read Text File Called Inputtxt String Characters Upperc Q32561711 . . .

    Write an ARM program in ARMSim# that will do the following:​

    Read the text from a file called “input.txt” as a string ofcharacters
    Uppercase every consonant
    Replace all vowels with an asterisk (*)
    Output the new string from memory to a file called”output.txt”
    For example:
    “input.txt” contains “Blind love couldn’t win as the facts all camein. But I know I’ll again chase after wind. What have I got if nota thought?”
    “output.txt” should contain “BL*ND L*V* C**LDN’T W*N *S TH* F*CTS*LL CAME *N. B*T * KN*W *’LL *G**N CH*S* *FT*R W*ND. WH*T H*V* *G*T *F N*T * TH**GHT?”
    Meeting the above requirements is a bare minimum for theassignment. In order to get full credit, your program should:

    have appropriate comments
    check for errors
    have a readable output
    Please submit a single file called “project2.s” to theassignment.

    Expert Answer


    . . .


    view full answer