Scope, authority, and forensic purpose
Define exactly what the fictional investigation may answer, which systems and evidence categories are included, and what remains excluded.
Bring the entire Digital Forensics Concepts module together in one safe fictional case. Define scope, register evidence, reconstruct chronology, analyze endpoint and account context, reason about temporary and persistent evidence, correlate sources, document uncertainty, apply ethical limits, build a professional report, simulate review and correction, and create a public-safe portfolio artifact.
Lesson Progress
High School Advanced • A8: Digital Forensics Concepts • Lesson 10 of 10
Readiness Check
0/6 ready
Professional Hook
A fictional investigation can produce a neat story quickly: Account A received a temporary role, authenticated, a workflow event happened, and a supplier change occurred nearby in time. But a professional forensic conclusion must survive shared-device ambiguity, source degradation, delayed evidence, incomplete supplier provenance, browser transformation, notification-awareness limits, and ethical scope boundaries.
The goal of this capstone is therefore not to force one dramatic explanation. It is to build the strongest evidence-bounded account possible. A capstone can be successful even when some answers remain Unknown, because disciplined uncertainty is part of professional forensic work.
Weak capstone goal
“Find the person responsible and prove the cause.”
Professional capstone goal
“Answer the approved fictional forensic questions as strongly as the supplied evidence allows while preserving uncertainty, ethics, traceability, and non-proof limits.”
Learning Objectives
Objective 1
Integrate fictional scope, authorization, evidence integrity, chronology, endpoint, memory/storage, browser/account, correlation, reporting, and ethics concepts into one coherent forensic reasoning workflow.
Objective 2
Build a fictional evidence register that preserves evidence identity, source owner, source health, provenance, time type, transformation, privacy, availability, integrity state, and non-proof limitations.
Objective 3
Develop a defensible fictional chronology and correlation model that separates event order, evidence availability, account or device association, person attribution, causation, intent, and impact.
Objective 4
Create a professional fictional forensic report package with evidence-linked findings, confidence, limitations, alternatives, Unknowns, reviewer comments, versioning, corrections, distribution, retention, and reopen criteria.
Objective 5
Demonstrate ethical restraint by recognizing fictional stop conditions, unrelated findings, third-party data, scope changes, conflicts, privacy limits, and cases where the strongest professional answer is Unknown or no further investigation.
Module Integration
Define exactly what the fictional investigation may answer, which systems and evidence categories are included, and what remains excluded.
Preserve evidence identity, provenance, ownership, transformations, handoffs, versioning, and decision traceability.
Separate event, receipt, processing, review, and decision times while preserving source health and uncertainty.
Interpret supplied endpoint evidence at the device, account, session, application, process, file, configuration, and update level without over-attributing a person.
Reason about temporary, persistent, synchronized, backed-up, archived, expired, and unavailable evidence states.
Separate authentication, session, browser context, notification, synchronization, recovery, and person-level attribution.
Connect fictional identity, endpoint, application, service, supplier, and audit records without double-counting or forcing causal stories.
Convert evidence and reasoning into a professional report with confidence, limitations, alternatives, review, corrections, and audience-specific summaries.
Apply purpose limitation, necessity, proportionality, minimization, privacy, conflicts, stop conditions, retention, and disclosure boundaries.
Case File
Fictional organization Northbridge uses Service S for a support workflow involving shared Endpoint D-17 and Account A.
A temporary support role for Account A became effective at 13:42 and was scheduled to expire at 15:00.
A fictional authentication event associates Account A with Session S at 14:01.
A fictional workflow event occurs at 14:04 while Session S is represented as active.
The application source is Degraded from 14:02 through 14:18.
A supplier note received later reports a dependency-state change at 13:58, but its original creation-time provenance remains Conditional.
Endpoint D-17 is an approved shared workstation, so physical-person attribution is not established by device association alone.
A role-change notification was generated before Session S, but no acknowledgement record establishes that a person saw or accepted it.
Fake Dashboard
Northbridge A8 capstone — invented values only
Evidence items
10
Identity, endpoint, application, supplier, browser, backup, notification
Material limitations
6
Shared device, Degraded source, Conditional provenance, transformed browser summary, awareness Unknown, version-limited backup
Core findings
6
Account/session, workflow overlap, supplier timing, absence limit, notification state, browser context
Ethical stop points
4
New service, unrelated personal detail, conflict, secondary purpose
Evidence Register
Source
Fictional identity governance record
Owner
Identity owner
Time
13:42 event time
Provenance
Direct supplied record
Integrity
Verified within fictional exercise
Supports
Temporary support role became effective for Account A.
Limitation
Does not prove the account was used or that a specific person acted.
Source
Fictional identity authentication record
Owner
Identity owner
Time
14:01 event time
Provenance
Direct supplied record
Integrity
Verified within fictional exercise
Supports
Account A successfully entered Session S.
Limitation
Does not independently establish the physical person.
Source
Fictional endpoint session record
Owner
Endpoint owner
Time
14:01–14:19 interval
Provenance
Supplied session summary
Integrity
Conditional due to summary representation
Supports
Session S was represented on shared Endpoint D-17.
Limitation
Does not prove continuous physical presence or manual activity.
Source
Fictional application record
Owner
Application owner
Time
14:04 event time
Provenance
Supplied application event
Integrity
Usable with source-health limitation
Supports
Workflow W recorded one unusual state transition.
Limitation
Source degradation limits completeness and does not prove cause.
Source
Fictional monitoring quality record
Owner
Application owner
Time
14:02–14:18 interval
Provenance
Direct supplied health record
Integrity
Verified within fictional exercise
Supports
The application source was Degraded during the central review period.
Limitation
Does not identify which unseen events, if any, occurred.
Source
Fictional supplier note
Owner
Supplier owner
Time
13:58 reported event / 14:39 receipt
Provenance
Forwarded note; original creation-time provenance incomplete
Integrity
Conditional
Supports
The note reports an earlier dependency-state change.
Limitation
Does not prove supplier causation, fault, or exact creation time.
Source
Fictional account notification record
Owner
Identity owner
Time
13:46 event time
Provenance
Direct supplied notification record
Integrity
Verified within fictional exercise
Supports
A role-change notification was generated before the session.
Limitation
Does not establish acknowledgement, awareness, consent, or action.
Source
Fictional asset record
Owner
Endpoint owner
Time
Current case context
Provenance
Direct supplied asset record
Integrity
Verified within fictional exercise
Supports
D-17 is an approved shared workstation.
Limitation
Does not identify which approved user physically controlled the device.
Source
Fictional browser navigation summary
Owner
Browser/application owner
Time
14:03–14:06 interval
Provenance
Transformed summary
Integrity
Conditional due to transformation
Supports
The Support Console and Workflow Review page were represented in browser context.
Limitation
Does not prove person-level navigation, intent, attention, or causation.
Source
Fictional backup summary
Owner
Storage owner
Time
13:30 version time
Provenance
Supplied retained-state summary
Integrity
Verified for represented version
Supports
Application Q state can be described as of 13:30.
Limitation
Does not represent changes after the backup point.
Fake SOC Alert
Source: Supplied fictional evidence • Time: Fictional review window
Chronology
| Time | Type | Evidence | Event | Confidence | Limit |
|---|---|---|---|---|---|
| 13:30 | Version time | EV-10 | Fictional backup represents Application Q state. | High | Does not cover later changes. |
| 13:42 | Event time | EV-01 | Temporary support role becomes effective for Account A. | High | Role state does not prove later account use. |
| 13:46 | Event time | EV-07 | Role-change notification is generated. | High | Acknowledgement and awareness remain Unknown. |
| 13:58 | Reported event time | EV-06 | Supplier note reports dependency-state change. | Conditional | Original creation-time provenance incomplete. |
| 14:01 | Event time | EV-02 / EV-03 | Account A authenticates and Session S begins on shared D-17. | High for account/session association | Physical-person attribution unresolved. |
| 14:02–14:18 | Source-health interval | EV-05 | Application source operates in a Degraded state. | High | Missing application records cannot support strong absence claims. |
| 14:03–14:06 | Event interval | EV-09 | Support Console and Workflow Review are represented in browser context. | Moderate | Manual navigation and intent not established. |
| 14:04 | Event time | EV-04 | Workflow W records an unusual state transition. | Moderate | Application-source degradation and causation limit apply. |
| 14:19 | Session end | EV-03 | Session S is represented as ended. | Moderate | Does not explain every action within the interval. |
| 14:39 | Receipt time | EV-06 | Supplier note reaches the investigation. | High about receipt | Receipt time differs from reported supplier event time. |
Fake Log Panel
13:42 | IDENTITY | evidence=EV-01 | account=Account-A | temp-role=effective 13:46 | NOTIFICATION | evidence=EV-07 | role-change=generated | acknowledgement=Unknown 13:58 | SUPPLIER | evidence=EV-06 | dependency-state=changed | provenance=Conditional 14:01 | AUTH | evidence=EV-02 | account=Account-A | result=success 14:01-14:19 | ENDPOINT_SESSION | evidence=EV-03 | endpoint=D-17 | shared=true | physical_user=Unknown 14:02-14:18 | SOURCE_HEALTH | evidence=EV-05 | application=Degraded 14:03-14:06 | BROWSER | evidence=EV-09 | context=Support-Console+Workflow-Review | intent=Unknown 14:04 | APPLICATION | evidence=EV-04 | workflow=Workflow-W | state=unusual-transition 14:39 | RECEIPT | evidence=EV-06 | supplier-note-received | reported-event=13:58
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
Correlation Findings
Evidence
EV-02 + EV-03 + EV-08
Finding
Account A and Session S correlate with shared Endpoint D-17 during the approved review period.
Alternative
Shared-device use and stale-session continuation limit person-level attribution.
Does not prove
The evidence does not independently identify the physical person controlling D-17.
Evidence
EV-03 + EV-04 + EV-05
Finding
The supplied workflow event occurs during the interval represented as an active Account A session.
Alternative
The event may be unrelated to the account session despite temporal overlap.
Does not prove
Temporal overlap does not establish causation or intent.
Evidence
EV-06 + EV-04
Finding
The supplier note reports a dependency-state change before the workflow event.
Alternative
The supplier event may be correctly timed but unrelated to Workflow W.
Does not prove
The supplied evidence does not establish supplier fault or causation.
Evidence
EV-05 + application gap
Finding
The Degraded application source cannot support complete absence conclusions from 14:02 through 14:18.
Alternative
An event may have occurred without being represented in the source.
Does not prove
Missing application evidence does not prove event absence.
Evidence
EV-07 + no acknowledgement record
Finding
A role-change notification was generated before Session S.
Alternative
The notification may not have been seen or understood.
Does not prove
Generation does not establish acknowledgement, awareness, consent, or acceptance.
Evidence
EV-09 + EV-03 + EV-08
Finding
The Support Console was represented in browser context during the session interval.
Alternative
Automation, synchronization, prior state, or shared-device use may explain the browser representation.
Does not prove
The evidence does not establish physical-user navigation, attention, intent, or causation.
Analyze the Evidence
Ethical Decisions
One fictional record references Service T outside current scope.
Decision
Record the reference but do not investigate Service T under current authority.
Owner
Investigation coordinator
Reopen trigger
A qualified owner determines that Service T is materially necessary to answer the approved question.
A fictional transformed browser summary contains unrelated personal activity.
Decision
Exclude and minimize the unrelated detail and follow the fictional privacy process.
Owner
Privacy reviewer
Reopen trigger
Only under a separate qualified purpose and authority decision.
A fictional reviewer previously approved a change now under evaluation.
Decision
Disclose the relationship and use independent review for material conclusions.
Owner
Decision owner
Reopen trigger
Conflict ownership changes or independent reviewer becomes unavailable.
A manager asks to reuse the forensic evidence for unrelated employee-performance review.
Decision
Stop secondary use under the incident-response purpose.
Owner
Governance / privacy owner
Reopen trigger
A separate lawful, proportionate, purpose-specific fictional decision is documented.
Scenario Decision Lab
During the fictional capstone, one supplied record references Service T. Service T is outside current scope, the approved account/session question can already be answered without investigating it, and reviewing Service T would expose unrelated third-party information.
Professional Report Package
Deliverable 1
Question, strongest conclusion, confidence, material Unknowns, service effect, owner decision, and next action.
Deliverable 2
Purpose, requesting owner, decision owner, scope version, systems, identities, time window, evidence categories, exclusions, and stop conditions.
Deliverable 3
Evidence IDs, owners, source health, provenance, integrity, time type, transformation, privacy, support, and limitations.
Deliverable 4
Event, receipt, processing, review, and decision time distinctions; source-health intervals; gaps; confidence; non-causal language.
Deliverable 5
Relationship questions, supporting evidence, duplicate state, contradiction, alternatives, confidence, attribution and causation limits.
Deliverable 6
Finding ID, evidence references, conclusion, confidence, limitation, alternative, Unknown, and non-proof statement.
Deliverable 7
Necessity, proportionality, minimization, sensitive information, third-party issues, conflicts, stop conditions, purpose changes, retention, disclosure.
Deliverable 8
Reviewers, comments, prior wording, corrected wording, reason, approval state, redistribution, retention, and reopen criteria.
Deliverable 9
Fully invented scenario, general defensive reasoning, safe diagrams or cards, limitations, ethics, lessons learned, and no real system detail.
Review Gate
Does the capstone clearly state the fictional purpose and authority before evidence analysis begins?
Can every material finding be traced to evidence IDs and source-health context?
Are event, receipt, processing, review, and decision times kept distinct?
Are shared-device, stale-session, automation, synchronization, and backup-version limits visible?
Does the correlation matrix distinguish independent evidence from derived or duplicate records?
Does every major finding include confidence, limitation, alternative explanation, and non-proof language?
Are Degraded or missing-source intervals prevented from becoming unsupported absence claims?
Are account association, person attribution, causation, intent, and impact kept separate?
Are scope changes, sensitive information, third parties, conflicts, new purposes, retention, and disclosure decisions documented?
Is the public portfolio version fully fictional and free of real logs, screenshots, accounts, systems, suppliers, or private details?
Scenario Decision Lab
The fictional capstone report is complete. Evidence strongly supports Account A and Session S association with shared D-17, moderately supports workflow overlap, conditionally supports an earlier supplier dependency change, and leaves physical-person attribution plus causation unresolved.
Safe Fictional Capstone Lab
Complete all nine phases below using only the invented Northbridge case and evidence on this page. Do not access, inspect, collect, query, monitor, export, capture, image, extract, recover, unlock, bypass, correlate, or investigate any real device, account, browser, service, application, storage system, network, supplier, message, organization, classmate, teacher, family member, or other person.
Capstone boundary
This capstone is a classification, reasoning, writing, ethics, and reporting exercise using only invented, pre-supplied evidence. It does not authorize real forensic collection, evidence acquisition, memory capture, storage imaging, file recovery, browser review, account access, log querying, network capture, extraction, surveillance, bypass, configuration changes, or investigation of real people or systems.
Advanced Challenge
The fictional leadership team accepts the account/session finding but wants you to identify the person and the cause. Your evidence cannot support either conclusion with confidence. Your challenge is to demonstrate why the capstone is complete even without those answers.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fully fictional A8.10 Digital Forensics Capstone Case Package for Northbridge. Include a purpose statement; authority statement; primary forensic question; decision owner; investigation coordinator; scope version; included systems, identities, services, evidence categories, and time window; explicit exclusions; stop conditions; evidence register with at least ten invented evidence items; source owners; source health; provenance; integrity state; time type; availability; transformation; privacy limit; chronology; at least six correlation findings; confidence; alternative explanations; non-proof statements; endpoint interpretation; temporary-versus-persistent evidence reasoning; browser/account interpretation; supplier evidence; one Degraded-source absence limit; one shared-device person-attribution Unknown; one notification-awareness Unknown; one supplier-causation Unknown; ethical boundary register; unrelated-finding referral; third-party minimization; conflict disclosure; recusal or independent-review decision; secondary-purpose stop decision; retention plan; disclosure matrix; executive summary; technical findings section; privacy/governance summary; leadership summary; reviewer comments; one material correction; prior and corrected wording; version history; redistribution; reopen criteria; lessons learned; and a public-safe portfolio summary. Every organization, person, account, endpoint, service, supplier, application, source, evidence item, timestamp, finding, reviewer, decision, and outcome must be invented.
Confidence / Readiness Reflection
Rate your readiness from 1 to 5 across all nine A8 skill areas. Before moving to the module test, you should be able to explain not only what a fictional evidence item supports, but also how source health, timing, provenance, transformation, privacy, ethics, and non-proof limits change the strength of the final conclusion.
Key Takeaways
Safety Boundary
Nothing in A8.10 authorizes access, investigation, monitoring, querying, log collection, browser inspection, account access, credential use, password recovery, secret recovery, private-message review, device access, memory capture, storage imaging, file recovery, packet capture, extraction, decryption bypass, unlocking, surveillance, configuration changes, live acquisition, or examination involving any real device, account, application, service, supplier, storage system, network, organization, incident, classmate, teacher, family member, or other person. Use only the fully invented, pre-supplied Northbridge capstone material.
A8 Lessons Complete
You have now completed all ten lessons in Digital Forensics Concepts. The module test will check whether you can apply the full A8 framework across scope, evidence integrity, timeline analysis, endpoint artifacts, memory and storage, browser and account activity, correlation, reporting, ethics, and capstone reasoning while preserving the same defensive and non-invasive boundaries.