# Lab 13.3: Digital Data Forensic Techniques > CompTIA Security+ Module 13 case study by Johnathan Belcher. ## Overview This lab focused on how digital evidence is identified, preserved, collected, analyzed, and presented in a way that supports investigations and legal requirements. I learned how forensic best practices protect evidence integrity, strengthen non-repudiation, and make forensic work useful in both on-premises and cloud environments. ## What I Learned - **Evidence Handling**: How legal hold, chain of custody, preservation, and documentation keep evidence reliable and defensible. - **Data Acquisition**: How to capture system images, logs, network traffic, hashes, screenshots, and witness statements for analysis. - **Integrity & Recovery**: How hashing, snapshots, data provenance, and recovery workflows help prove evidence has not been altered. - **Cloud Forensics**: Why cloud investigations add legal, jurisdictional, and chain-of-custody challenges that differ from on-premises analysis. ## Core Topics I Can Explain Confidently **Forensic Process & Evidence Control** - Identification, preservation, collection, examination, analysis, presentation, and decision - Legal hold and chain of custody requirements for admissible evidence - Order of volatility and why volatile evidence must be collected first - Bit-level imaging, hashes, and preservation of the source image **Analysis, Recovery, and Intelligence** - Hashing methods such as MD5, SHA, HMAC, and digital signatures - Evidence recovery from deleted space, cache files, and accessible disk space - Non-repudiation and how public-key cryptography supports attribution - Strategic intelligence and counterintelligence gathering for investigations ## Exercise Summary - **Motive, Opportunity, and Means**: How investigators build context around an incident. - **Documentation and Acquisition**: How to document evidence correctly and acquire data from images, logs, screenshots, and network activity without breaking integrity. - **Cloud, Recovery, and E-Discovery**: How cloud investigations differ from on-premises work and how e-discovery supports legal review and structured evidence handling. ## E-Discovery Reference Model The 8-step EDRM workflow used to manage electronically stored information during an investigation: Identification, Preservation, Collection, Process, Review, Analyze, Production, Presentation. ## Professional Value - Stronger investigative mindset — treating evidence carefully, verifying integrity, and preserving chain of custody. - Better legal awareness of e-discovery, legal hold, and breach notification requirements. - Connects disk, network, cloud, and memory-related evidence into one investigation flow. - Clearer documentation habits: timestamps, hashes, provenance, and standardized evidence labeling. ## Security+ Alignment Supports Security+ Objective 4.5, focusing on evidence handling (documentation, chain of custody, preservation, legal hold, integrity verification), acquisition and recovery (system imaging, network logs, order of volatility, data recovery), and governance and analysis (cloud vs. on-premises, non-repudiation, e-discovery and presentation).