NIST Guidelines, Policy Management & Evidence Handling
Four-phase forensic process, evidence collection, order of volatility, and documentation.
TOPIC 5.7Volatile vs non-volatile evidence, file system artifacts, memory forensics, and log sources.
TOPICPolicy hierarchy, AUP, data classification, regulatory compliance (GDPR, HIPAA, PCI).
TOPIC 5.4PII, PHI, PCI data types, classification levels, DLP alerts, and breach response.
TOPICMTTD, MTTR, dwell time, tier responsibilities, SLAs, and coverage metrics.
TOPIC 5.5Baseline establishment, anomaly detection, server profiles, and SIEM integration.
TOPIC 5.8NIST IR phases, escalation matrices, containment strategies, and post-incident activities.
TOPICClass activity - collaborative incident identification and initial analysis exercise.
Configure logging, observe packet flow, and correlate network events with log entries.
Analyze DNS patterns, detect tunneling indicators, and extract IOCs from DNS logs.
Understand SQL injection from a defensive perspective for SOC detection awareness.
Parse log formats, identify security events, and build investigation timelines.
Complete all topics and labs, then take the Week 5 assessment to test your incident response and forensics knowledge.
Begin Evaluation