The ISACA Cybersecurity: Digital Forensics Online Course provides learners with a deep understanding of the principles and best practices of digital forensics. Throughout this course, learners will step through the process of conducting a complete investigation. You’ll explore the legal and ethical considerations of digital forensics including the chain of custody. You’ll also gain practical experience through a series of real-world simulations and exercises taught through our performance-based training.
At the completion of this course, learners will be able to:
- Define digital forensics
- Explain the evolution of networking and the purpose of digital forensics
- Describe the unique challenges of collecting forensic evidence from networks
- List the devices, media, and memory where evidence can be found
- Explain the OSCAR methodology for collecting digital evidence
- Explain laws applicable to digital forensics
- Explain guidelines for collecting digital evidence for specific devices and networks
- List guidelines for collecting and documenting evidence so that it is admissible in court
- List physical and logical tools used in digital forensics
- Explain how Kali Forensics is used to collect digital evidence
- Describe tools such as Wireshark, Tshark, dumpcap, and tcpdump that work with Kali Forensics
- Explain how case management software is used
- Explain how imaging tools are used in an investigation
- Describe the types of digital evidence and how they are stored
- Document where and how evidence is collected
- Describe how to establish and maintain a chain of custody
- Explain high-level concepts related to digital imaging, such as tools, formats, size, and compression
- Explain hashes and checksums
- Explain what to do with damaged drives
- Define remote access and remote forensics
- Identify tools used in remote forensics
- List the elements of a cyberforensic analysis
- Describe types of drives
- Explain partitions and volumes
- Explain file systems
- Recognize common antiforensic techniques
- Recognize common file modifications that could indicate suspicious activity
This course includes seven performance-based labs. A performance-based lab places the learner in a virtual environment where they execute common tasks to complete the lab objective. Each lab includes set-up information and learning aids to help guide learners through the lab.
Labs included in this course:
- Kali Forensics Introduction
- Digital Evidence Collection
- Network Forensics
- PCAP Forensics
- Memory Analysis
- Disk Analysis
- Remote Forensics
Learners will have access to the course for six months from date of purchase and will earn 12 CPEs upon completion. This course has a seat time of approximately 10 hours and is accessed via the Learning Access tab of your MyISACA dashboard.
Cancellation/Refund Policy
All purchases of online learning courses are final. Access to the online learning courses and materials is immediate upon purchasing; therefore no refunds or exchanges will be provided. Prices subject to change without notice.