Forensic examination: The methodical collection and analysis of digital evidence to reconstruct past events. This can include activities like recovering deleted files, analyzing system logs, extracting data from databases, or examining network traffic. The goal is to understand what actions were performed, by whom, and when to establish the facts of a case or incident.
Categories: CC D5: Security Operations | CCSP D3: Cloud Platform and Infrastructure Security | CISM D4: Incident Management | CISSP D7: Security Operations | Security+ D4: Security Operations | SSCP D4: Incident Response and Recovery
« Back to Glossary Index