Within the forensic process it is essential to document everything. This means that the hardware and system configuration (how cables are connected) should all be documented. This module will introduce you to hardware, various types of RAID, how to image and hash a drive, exact the contents of memory and understanding the system boot process. This is the first part in being able to analyze data as you should never use the original media in a forensic investigation.
Produce and verify a digital forensic image → LO #2
Recognize the various hardware components present in different computer systems → LO #2
Demonstrate acquisition of the Master Boot Record → LO #2
Comprehend the Digital Forensics Process → LO #3