ScholarQuill logoScholarQuillUniversity Notes
  • Notes
  • Past Papers
  • Blogs
  • Todo
Login
ScholarQuill logoScholarQuillUniversity Notes
Login
NotesPast PapersBlogsTodo
More
SubjectsDiscussionCGPA CalculatorGPA CalculatorStudent PortalCourse Outline
About
About usPrivacy PolicyReportContact
Notes
Past Papers
Blogs
Todo
Analytics
    Current Subject
    🧩
    Information Technology Infrastructure
    ITEC3128
    Progress0 / 56 topics
    Topics
    1. Overview: Definitions and Infrastructure management activities2. Evolutions of Systems since 1960s (Mainframes-to-Midrange-to-PCs-to-Client-server computing-to-New age systems) and their Management3. Growth of internet, current business demands and IT systems issues4. Complexity of today's computing environment5. Total cost of complexity issues6. Value of Systems management for business7. Factors to consider in designing IT organizations and IT infrastructure8. Determining customer's Requirements9. Identifying System Components to manage10. Exist Processes, Data, applications, Tools and their integration11. Patterns for IT systems management12. Introduction to the design process for information systems13. Current computing environment: Complexity of current computing, multiple technologies, multiple vendors, multiple users14. e-Waste disposal15. Total cost of ownership16. IT system Management: Common tasks in IT system management17. Approaches for organization Management18. Models in IT system design19. IT management systems context diagram20. Patterns for IT system Management21. Information system costs and benefits22. Capital budgeting for information system23. Real Options pricing models24. Limitation of financial models25. Service Delivery Processes: IT services continuity management26. Capacity management27. Availability management and service desk28. Service Support Management: Service support process29. Configuration Management30. Incident management31. Problem management32. Change management33. Release management34. Storage Management: backups, Archive, Recovery, Disaster recovery35. Space management36. Hierarchical storage management37. Network attached storage38. Storage area network39. Bare machine recovery40. Data retention41. Database protection42. Security Management: Introduction Security43. Identity management44. Single sign-on45. Access Management46. Basics of network security47. LDAP fundamentals48. Intrusion detection49. Firewall50. Security information management51. IT Ethics: Introduction to Cyber Ethics52. Intellectual Property53. Privacy and Law54. Computer Forensics55. Ethics and Internet56. Cyber Crimes
    ITEC3128›Computer Forensics
    Information Technology InfrastructureTopic 54 of 56

    Computer Forensics

    3 minread
    520words
    Beginnerlevel

    📘 Topic: Computer Forensics

    Subject: Information Technology Infrastructure


    1. 📌 Introduction

    With the increase in cybercrime such as hacking, data theft, fraud, and malware attacks, organizations need methods to investigate digital evidence. Traditional investigation methods are not enough for digital systems.

    👉 This need is fulfilled by Computer Forensics.


    2. ✅ Definition

    Computer Forensics is the process of identifying, collecting, preserving, analyzing, and presenting digital evidence from computers and other digital devices in a legally acceptable way.

    👉 Simple idea: It is like a “digital crime investigation system.”


    3. 🎯 Objectives of Computer Forensics

    • Investigate cybercrimes 🔍
    • Recover deleted or hidden data 💾
    • Preserve digital evidence safely 🔐
    • Identify attackers or unauthorized users 👤
    • Support legal and court proceedings ⚖️

    4. 🧩 Key Principles of Computer Forensics


    🔑 1. Preservation

    • Evidence must not be changed or damaged

    🔑 2. Integrity

    • Data must remain accurate and unaltered

    📊 Example:

    • Using hash values to verify files

    🔑 3. Chain of Custody

    • Proper record of who handled evidence and when

    🔑 4. Legality

    • Evidence must be collected legally to be valid in court

    5. ⚙️ Phases of Computer Forensics


    🔍 1. Identification

    • Detect possible sources of evidence

    📊 Example:

    • Hard drives, emails, logs

    🔍 2. Collection

    • Gather digital evidence safely

    🔍 3. Preservation

    • Secure evidence to avoid modification

    🔍 4. Analysis

    • Examine data for suspicious activity

    🔍 5. Documentation

    • Record all findings and procedures

    🔍 6. Presentation

    • Present evidence in court or reports

    📊 Diagram Description

    Identification → Collection → Preservation → Analysis → Documentation → Presentation
    

    6. 🧠 Real-Life Example

    A company suspects employee data theft:

    • Forensic experts analyze employee computer
    • Deleted files are recovered
    • Email logs are checked
    • Evidence is presented in court

    👉 Result:

    • Cybercriminal is identified and prosecuted

    7. ⚙️ Tools Used in Computer Forensics

    • Disk imaging tools
    • Data recovery software
    • Network analysis tools
    • Password recovery tools
    • Log analysis tools

    8. 📌 Importance of Computer Forensics

    • Helps solve cybercrimes
    • Recovers lost or deleted data
    • Provides legal evidence
    • Improves cybersecurity
    • Protects organizations from fraud

    9. ⚠️ Challenges

    • Encrypted data 🔐
    • Large volume of digital data 📊
    • Rapidly changing technology ⚡
    • Legal restrictions ⚖️
    • Risk of evidence tampering

    10. 🔄 Computer Forensics vs Cybersecurity

    Feature Computer Forensics Cybersecurity
    Purpose Investigate crimes Prevent attacks
    Focus Post-incident analysis Protection & defense
    Outcome Evidence collection System security

    11. 📝 Likely Exam Questions

    ⭐ Short Questions:

    1. Define computer forensics.
    2. What is chain of custody?
    3. What is digital evidence?
    4. What is data preservation?
    5. Give one use of computer forensics.

    ⭐ Long Questions:

    1. Explain computer forensics process with diagram.
    2. Discuss principles of computer forensics.
    3. Describe phases of digital investigation.
    4. Differentiate between computer forensics and cybersecurity.
    5. Explain importance of computer forensics in IT systems.

    12. 📌 Quick Summary / Conclusion

    • Computer forensics is the investigation of digital crimes using scientific methods.

    • It involves:

      • ✔ Collecting evidence
      • ✔ Preserving data
      • ✔ Analyzing digital systems
      • ✔ Presenting findings in court

    👉 Final Idea: Computer forensics is essential for detecting cybercrime, protecting digital evidence, and supporting legal justice in IT systems.


    ✅ Exam Tip: Always include:

    • Definition
    • Phases (very important)
    • Diagram
    • Principles
    • Real-life example for full marks
    Previous topic 53
    Privacy and Law
    Next topic 55
    Ethics and Internet

    Past Papers

    Open this section to load past papers

    Click on Show Past Papers to see past papers.
    On This Page
      Reading Stats
      Est. reading time3 min
      Word count520
      Code examples0
      DifficultyBeginner