Course

Credit Type:
Course
ACE ID:
DDCI-0011
Version:
3
Organization's ID:
NTC
Location:
Classroom-based
Length:
5 days (40 hours)
Minimum Passing Score:
70
ACE Credit Recommendation Period:
Credit Recommendation & Competencies
Level Credits (SH) Subject
Lower-Division Baccalaureate 3 Network Forensic Analysis
Description

Objective:

The course objective is for students to explain basic theory, technologies, and components that facilitate network data transmission; examine network traffic and previously captured data; perform a logical and physical assessment of a network to identify potential witness devices and the data they contain; assess a network and identify the proper placement of a network monitoring sensor; and configure network data acquisition tools.

Learning Outcomes:

  • Analyze network traffic.
  • Understand how the different network layers affect network monitoring.
  • Understand how network traffic utilizes different ports and their protocols.
  • Configure Wireshark to identify common network traffic and protocols.
  • Analyze packet headers using Wireshark.
  • Describe witness devices.
  • Determine the placement of a network monitoring workstation.
  • Interpret the difference between a trap and trace and a full capture.
  • Use protocol methodologies to retrieve captured data.
  • Analyze file transfer traffic.
  • Evaluate indicators of compromise (IOC).
  • Understand the components of packet headers.
  • Describe the types of network log content that can be recovered from common witness devices.
  • Determine the placement of a firewall on a network diagram.
  • Determine the placement of a router on a network diagram.
  • Explain the concept of remote logging.
  • Analyze a network diagram to identify potential witness devices.
  • Recall the steps involved in network monitoring and identify the appropriate information from onsite personnel questioning.
  • Describe the build of a monitoring workstation, and how the components affect the performance of the monitoring device.
  • Explain how to install a physical tap.
  • Conduct a physical assessment for placing a network monitoring workstation.
  • Configure and use Wireshark.
  • Conduct full packet capture using tcpdump.
  • Analyze web traffic.
  • Understand how to prevent command and control.
  • Understand how information is processed in relation to the TCP/IP model.
  • Determine the placement of a switch on a network diagram.

General Topics:

  • Introduction to Network Traffic
  • Networks and Witness Devices
  • Assessment and Sensor Placement
  • Capture
  • Analysis
Instruction & Assessment

Instructional Strategies:

  • Classroom Exercise
  • Computer Based Training
  • Discussion
  • Lectures
  • Practical Exercises

Methods of Assessment:

  • Examinations
Supplemental Materials
Equivalencies

Other offerings from DC3 Cyber Training Academy