From the course: CCNA Cybersecurity (200-201) v1.2 Cert Prep
Unlock this course with a free trial
Join today to access over 25,200 courses taught by industry experts.
Artifact elements
From the course: CCNA Cybersecurity (200-201) v1.2 Cert Prep
Artifact elements
(gentle music) - [Kevin] Our focus in this video is on artifact elements. So what exactly is an artifact element? Well, in digital forensics and security monitoring, an artifact is any piece of information or data stored on a digital device or observed in network traffic that's going to give us some sort of insight into usage and activities performed. And these are not just files. They can be entries in system logs, browser histories, metadata associated with files, remnants of deleted items, or patterns of network communication. And each artifact holds potential clues about timelines, user actions, or external interactions, that form the building blocks for investigating security incidents and identifying alerts. And one of the most fundamental artifact elements is the IP address. An IP address serves as a unique identifier for a device on the network, much like a street address for a house. In any network communication, there's a source IP address, the device sending the data. And a…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
(Locked)
Module 4: Network traffic analysis and interpretation1m 18s
-
(Locked)
Security event sources5m 26s
-
(Locked)
Alert classification4m 6s
-
(Locked)
Deep packet inspection (DPI)3m 53s
-
(Locked)
Comparing traffic-capture methods and NetFlow analysis4m 30s
-
Wireshark PCAP file analysis for Telnet flow2m 56s
-
(Locked)
Wireshark PCAP file analysis for malware infection8m 56s
-
(Locked)
Interpreting protocol headers7m 20s
-
(Locked)
Artifact elements7m 37s
-
(Locked)
Regular expressions5m 32s
-
(Locked)
-
-
-