Course

Credit Type:
Course
ACE ID:
DDCI-0002
Version:
5
Organization's ID:
CIRC
Location:
Classroom-based
Length:
2 weeks (80 hours)
Minimum Passing Score:
70
ACE Credit Recommendation Period:
Credit Recommendation & Competencies
Level Credits (SH) Subject
Lower-Division Baccalaureate 3 Incident Response
Description

Objective:

The course objective is to prepare students in cyber incident response and evidence collection. In this course, students are provided various scenarios to understand and develop response protocols in a real-world environment. Using trusted forensic tools, students identify and extract digital evidence from various devices such as computers, cell phones and small form factor digital storage devices. Students are taught how to properly document evidence using lawful, professional techniques to ensure the legal admissibility of the seized evidence.

Learning Outcomes:

  • Build a responder toolkit in preparation for an incident response after reviewing a case jacket and discussing relevant information.
  • Respond to a forensic incident and assume control of the environment using best practices.
  • Collect digital data from a live system.
  • Acquire a bit-for-bit image of digital media devices.
  • Acquire data from mobile devices.
  • Describe best practices used to package, track, transport, and store evidence.

General Topics:

  • Collecting Forensic Data from a Live System
  • Collecting Forensic Data During an Active Intrusion
  • Dead Box/Hard Drive Image Collection
  • Collecting loT and Mobile Devices as Digital Evidence
  • Evidence Handling
Instruction & Assessment

Instructional Strategies:

  • Audio Visual Materials
  • Case Studies
  • Classroom Exercise
  • Computer Based Training
  • Discussion
  • Laboratory
  • Lectures
  • Practical Exercises
  • Project-based Instruction

Methods of Assessment:

  • Case Studies
  • Examinations
Supplemental Materials
Equivalencies

Other offerings from DC3 Cyber Training Academy