Assignment Objectives
• To understand the principles of digital forensics.
• To apply forensic tools and techniques in real-world scenarios.
• To analyze cybercrime cases using forensic methodologies.
• To evaluate digital evidence and prepare forensic reports.
• To develop analytical and investigative skills.
Bloom’s Taxonomy Mapping:
Bloom’s Level Learning Outcome
Remembering Understanding basic digital forensic concepts
Understanding Explaining forensic procedures and laws
Applying Applying forensic tools and methods
Analyzing Analyzing digital evidence and cybercrimes
Evaluating Evaluating forensic findings and reports
Case-Based Questions
A mid-sized IT company reports unauthorized access to its internal servers. Several confidential files were exfiltrated. The system was powered ON when the forensic team arrived.
Questions:
Identify the type of digital evidence involved in this case.
Explain the forensic investigation life cycle applicable here.
Justify whether live or dead acquisition should be performed.
Explain the importance of chain of custody in this scenario.
CLO Mapping: CO1, CO2
Bloom’s Level: Understand → Apply → Analyze
During a cybercrime investigation, the defense claims that the digital evidence was tampered with during acquisition.
Questions:
What forensic principles were possibly violated?
How do hashing algorithms (MD5, SHA-256) ensure integrity?
Suggest proper evidence handling and documentation procedures.
CLO Mapping: CO2, CO5
Bloom’s Level: Apply → Analyze → Evaluate
A suspect is accused of manipulating financial records. The hard disk shows deleted files and suspicious timestamps.
Questions:
Explain how file carving can help retrieve evidence.
Differentiate between FAT and NTFS in forensic analysis.
Which tool—Autopsy or FTK Imager—would be more suitable and why?
CLO Mapping: CO3
Bloom’s Level: Understand → Apply → Analyze
A system infected with ransomware was shut down abruptly.
Questions:
What volatile data could have been lost?
Explain the role of RAM acquisition in malware analysis.
How does the Volatility Framework assist investigators?
CLO Mapping: CO3, CO4
Bloom’s Level: Apply → Analyze
An organization notices abnormal outbound traffic at midnight every day.
Questions:
Which network forensic tools can be used to analyze traffic?
Explain the role of packet capturing in forensic investigation.
How can Wireshark and Snort help identify intrusions?
CLO Mapping: CO3, CO4
Bloom’s Level: Apply → Analyze
A suspect’s smartphone is seized in a cyberstalking case.
Questions:
What types of data can be extracted from mobile devices?
Differentiate between Android and iOS forensic challenges.
Explain the importance of SIM and app data analysis.
CLO Mapping: CO3, CO4
Bloom’s Level: Understand → Apply
An employee fell victim to a phishing email causing financial loss.
Questions:
What email header information is useful in investigation?
Explain the role of email forensics in cybercrime.
How can forensic tools trace the email source?
CLO Mapping: CO4
Bloom’s Level: Analyze → Evaluate
Data hosted on a cloud server is suspected to be altered by an insider.
Questions:
What challenges arise in cloud forensics?
Explain the limitations of traditional forensic tools in cloud environments.
Suggest solutions to ensure forensic readiness in cloud systems.
CLO Mapping: CO4, CO5
Bloom’s Level: Analyze → Evaluate
A hospital system is locked due to a ransomware attack.
Questions:
Explain the forensic steps to investigate ransomware.
What role does memory and disk forensics play here?
How can future ransomware attacks be prevented?
CLO Mapping: CO4, CO5
Bloom’s Level: Analyze → Evaluate
A forensic expert must submit evidence in court.
Questions:
What are the components of a forensic investigation report?
Explain the importance of legal compliance and documentation.
How does improper reporting affect court proceedings?
CLO Mapping: CO5
Bloom’s Level: Evaluate → Create
NAAC Alignment
• Supports Outcome-Based Education (OBE)
• Encourages experiential and case-based learning (NAAC Criterion 1.3)
• Enhances analytical and problem-solving skills
• Improves employability and industry readiness