1. Explain Digital Evidence as Alibi with an example.
2. Explain Digital Evidence on Unix systems.
3. Explain Cyber Stalking and IP tracing with example?
4. Explain Evidence on Physical/Data Link layers?
5. Differentiate Network and traditional forensics.
6. Differentiate reconstruction and recovery.
7. Explain Investigative Reconstruction and its role in cyber investigations.
8. Explain Digital Evidence on Windows systems.?
9. Explain Forensics principles to computers.?
10. Explain Evidence on Network/Transport layers
[Link] Forensics principles to networks.
12. What is the Role of hash values in reconstruction? Explain with
Example?
[Link] the importance of IP address analysis in tracking malicious
activity.
[Link] does a forensic examiner analyze ARP (Address Resolution
Protocol) cache to detect an ARP spoofing attack?
[Link] the key differences between analyzing Physical Layer evidence
and Network Layer evidence.