Lesson 10: Incident Response and Digital Forensics
Week of Tue, Nov 17 · lesson closes Mon, Nov 23
Take Meerk's quiz for Lesson 10
This lesson's items
Exact due times are in Canvas.
Watch — Professor Messer
Watch — Professor Messer: Incident Response (SY0-701)
Free, independent educational resource. Not affiliated with or endorsed by CompTIA. Watch, then read the notes below.
Know these cold
- IR phases (NIST SP 800-61): Preparation → Detection → Containment → Eradication → Recovery → Lessons Learned.
- Order of volatility for forensic collection: CPU registers/cache → RAM → running processes → network state → disk → logs → off-site backups.
- Chain of custody: documented evidence handling from collection through trial. Write blockers prevent forensic tools from altering evidence. Hashing evidence (SHA-256) proves integrity.
Meerk's quiz — open the Lesson 10 gate
10 questions, no time limit. 85% on your first attempt in a 24-hour window opens the gate. Retakes inside the window are practice — they help you learn, they don't count. Work alone; the point is to know it, not to have seen it.
Dinner Table Question
Ask at home: After a ransomware attack, should a company pay the ransom — why or why not?
En español: Después de un ataque de ransomware, ¿debería una empresa pagar el rescate — por qué sí o no?