Question
Write one neutral question that can be answered from supplied fictional evidence without assuming compromise, guilt, intent, cause, or impact.
Required output
One sentence describing the exact uncertainty to resolve.
Learn how professional fictional investigations begin before evidence interpretation: define the decision question, confirm authority, state purpose, set boundaries, choose only necessary evidence categories, protect privacy, assign owners, document exclusions, and create stop conditions that prevent curiosity from becoming uncontrolled scope.
Lesson Progress
High School Advanced • A8: Digital Forensics Concepts • Lesson 1 of 10
Readiness Check
0/6 ready
Professional Hook
A fictional service owner asks a simple question: did Account A perform an unusual service action during a two-hour support window? The team is given four supplied records that directly relate to the account and service. A fifth record contains an unrelated personal message from another fictional user. The message happens to mention the same service, so it feels relevant.
A weak investigation says, “It might help, so review it.” A professional investigation asks something different: does the approved purpose require this record, is it covered by authority, is the personal content necessary, who owns that decision, and can the original question be answered without using it? Technical connection is not the same as investigative permission.
Weak approach
“Review anything connected to the account in case it becomes useful.”
Professional approach
“Use the minimum supplied evidence necessary to answer the approved question, document exclusions, and require a new owner decision before purpose or scope expands.”
Learning Objectives
Objective 1
Translate a vague fictional concern into one neutral, answerable forensic question tied to a legitimate decision need.
Objective 2
Define fictional investigative authority, purpose, systems, identities, time range, evidence categories, recipients, owners, exclusions, and stop conditions before analysis begins.
Objective 3
Separate in-scope, conditionally in-scope, excluded, out-of-scope, unknown, and scope-change items using evidence and ownership rather than curiosity.
Objective 4
Recognize how scope creep, unsupported attribution, overcollection, vague authority, and privacy exposure can weaken both forensic quality and trust.
Objective 5
Create a versioned fictional investigation charter that connects question, scope, evidence needs, privacy, source health, review, escalation, and closure.
Why It Matters
Investigative scope is sometimes treated like paperwork added after technical work. In professional practice, scope is one of the controls that makes the work defensible. It tells reviewers why the investigation exists, what decision it is meant to support, which evidence categories are necessary, who authorized the work, which people and systems are included, what time period matters, which information must remain excluded, and when the team must stop.
Good scope also protects the investigation itself. If reviewers examine unrelated records, they create more information to secure, more privacy risk, more opportunities for confirmation bias, more conflicting details, more review debt, and more chances to lose the original question. More evidence is not automatically better evidence.
A bounded question makes it easier to judge whether each fictional record truly supports the decision.
Minimization prevents unrelated or excessive fictional personal information from entering the case.
Named owners can approve, reject, narrow, expand, review, correct, and close the investigation.
Future reviewers can understand what the team was allowed to examine and why each conclusion was reached.
Core Framework
A8.1 uses a seven-part model. The order matters because every later step depends on the earlier boundary. Evidence should not define its own purpose, and technical access should not define its own authority.
Write one neutral question that can be answered from supplied fictional evidence without assuming compromise, guilt, intent, cause, or impact.
Required output
One sentence describing the exact uncertainty to resolve.
Identify the fictional requesting owner, decision owner, evidence owners, reviewers, recipients, approval boundaries, and who may authorize changes.
Required output
A named fictional authority and ownership map.
State why the answer is needed and what decision it will support. The purpose should be specific enough to justify evidence use.
Required output
A purpose statement tied to one fictional decision.
Define identities, systems, services, evidence categories, time range, questions, exclusions, privacy limits, recipients, and stop conditions.
Required output
A versioned scope charter.
List only the supplied fictional evidence categories necessary to answer the question and document owner plus source-health expectations.
Required output
A minimum-necessary evidence plan.
Identify Blind sources, attribution limits, missing periods, conflicting records, unavailable owners, sensitive information, and conclusions that cannot be supported.
Required output
A limitations and Unknown register.
Describe what owner decision will be made from the findings and what state requires follow-up, scope change, closure, or reopening.
Required output
A decision and lifecycle statement.
Vocabulary
A neutral, bounded question that identifies what decision the supplied fictional evidence is intended to support.
The specific owner decision that requires evidence, such as whether a fictional account event occurred during a defined service window.
The rule that fictional evidence should be used only for the approved reason that justified the investigation.
The documented fictional permission and ownership that define who may request, review, decide, communicate, retain, or close an investigation.
The approved boundary covering fictional systems, identities, services, time periods, evidence categories, questions, recipients, and allowed review activity.
A fictional item intentionally kept outside the review because it is irrelevant, unauthorized, unnecessary, too sensitive, or owned by another process.
A predefined fictional condition that requires the review to pause, escalate, or obtain new approval before continuing.
A documented fictional modification to the original investigation boundary with reason, owner, evidence, approval, effective time, and new limits.
A high-level class of supplied fictional records that may help answer a bounded question, such as identity, application, endpoint, service, or audit evidence.
A description of whether a fictional source is Healthy, Conditional, Degraded, Blind, Conflicting, or Recovering for a specific conclusion.
A conclusion about who performed an action. In A8, attribution must remain limited to what the supplied fictional evidence genuinely supports.
A valid forensic state used when supplied fictional evidence cannot support either confirmation or absence.
Question Design
A forensic question should be narrow enough to guide evidence use but open enough to allow the evidence to contradict the initial concern. Words like attacker, stolen, malicious, compromised, or guilty can quietly turn a question into a conclusion.
Question pattern 1
Weak question
Who attacked the service?
Why it is weak
Assumes an attack, intent, one actor, and a conclusion before the evidence is reviewed.
Stronger question
What supplied fictional evidence supports or contradicts unusual activity associated with Account A during the approved service window, and what attribution limits remain?
Question pattern 2
Weak question
What did this user do?
Why it is weak
Targets a person broadly and encourages review of unrelated activity rather than one decision question.
Stronger question
Which supplied fictional account and service records document activity associated with Account A during the approved support window?
Question pattern 3
Weak question
Can we check everything connected to this alert?
Why it is weak
Uses technical relationship as a substitute for purpose, authority, minimization, and relevance.
Stronger question
Which supplied fictional evidence categories are necessary to decide whether the observed account event affected the defined service workflow?
Question pattern 4
Weak question
Did data get stolen?
Why it is weak
Assumes an outcome and fails to define which data, event, time, or evidence standard would support the conclusion.
Stronger question
Do the supplied fictional service and data-access records support that protected Dataset D was accessed during the approved review period, and what source-health limitations remain?
Question pattern 5
Weak question
Was the account compromised?
Why it is weak
Collapses many possible states into one label without defining the evidence required for the conclusion.
Stronger question
Which supplied fictional identity, session, approval, and service records support or contradict unauthorized use of Account A during the defined period?
Fake Dashboard
Northbridge evidence-reasoning exercise — invented values only
Open forensic questions
4
Two decision-ready, one Conditional, one awaiting owner clarification
Approved evidence categories
6
Identity, session, service, workflow, source health, owner statements
Scope-change candidates
2
One time-window question and one supplier evidence dependency
Excluded items
5
Unrelated personal content and unrelated services remain outside purpose
Authority
A fictional analyst may know that a record exists or may have technical capability to reach a system, but capability alone does not justify review. Professional authority asks who requested the work, who owns the evidence, what purpose is approved, who may authorize expansion, who reviews sensitive information, who receives the result, and who accepts residual uncertainty.
Owns
Decision need, business purpose, initial question, urgency, and why evidence review is necessary.
Does not automatically own
Automatic technical access, privacy exceptions, unlimited collection, or every specialist conclusion.
Owns
Question discipline, scope versioning, owner assignments, evidence references, decision chronology, and closure coordination.
Does not automatically own
Unilateral expansion into unrelated systems, identities, or sensitive information.
Owns
Meaning, provenance, source health, access rules, retention, limitations, and clarification for a fictional evidence category.
Does not automatically own
The final integrated conclusion by themselves.
Owns
Purpose limitation, minimization, sensitive-information handling, third-party exposure, access, retention, and distribution concerns.
Does not automatically own
Technical findings or business acceptance.
Owns
Service purpose, critical workflow, impact context, expected behavior, dependencies, continuity, and business interpretation.
Does not automatically own
Identity attribution or evidence custody.
Owns
Fictional policy, contractual, records, legal, or specialized governance questions when they arise.
Does not automatically own
Routine technical evidence interpretation outside their expertise.
Fake SOC Alert
Source: Supplied fictional evidence • Time: Fictional review window
Scope States
Binary scope can hide real uncertainty. Professional fictional investigations benefit from multiple states so teams can separate approved evidence from candidates, Unknowns, exclusions, and items that genuinely belong to another process.
| State | Meaning | Fictional Example | Handling |
|---|---|---|---|
| In scope | Explicitly covered by fictional purpose, authority, decision question, evidence plan, and time boundary. | Account A activity during the approved two-hour service-support window. | Review only supplied evidence categories necessary for the approved question. |
| Conditionally in scope | Potentially relevant, but use depends on an owner decision, additional authority, privacy review, source recovery, or evidence threshold. | A supplier record that may clarify the event but requires the fictional supplier owner to approve the request. | Record the dependency and do not treat the item as automatically reviewable. |
| Unknown | The team cannot yet determine whether the item belongs inside the review because evidence, ownership, purpose, or source health is incomplete. | A second identity linked by a delayed correlation source with no confirmed relationship. | Preserve uncertainty, assign an owner question, and avoid automatic expansion. |
| Excluded | Relevant enough to document but intentionally excluded under the current fictional purpose or privacy boundary. | Personal communication content unrelated to the approved service-state question. | Record the exclusion reason and do not inspect or redistribute unrelated content. |
| Out of scope | Not covered by the current fictional question, authority, time, systems, identities, or evidence categories. | Activity from another service outside the defined support window. | Do not include it merely because a technical relationship exists. |
| Scope-change candidate | New fictional evidence may justify expanding, narrowing, or otherwise changing the investigation boundary. | A traceable service record indicates the original time window may need to extend by fifteen minutes. | Document evidence, decision need, privacy effect, owner, proposed change, and approval before using the new boundary. |
Minimum-Necessary Evidence Planning
The strongest evidence plan does not ask, “What can we get?” It asks, “What supplied fictional evidence is necessary to answer the approved question?” This prevents evidence availability from silently expanding purpose.
Evidence category
Identity and approval records
Owner
Identity owner
Source health
Healthy
Minimum necessary
Account reference, role, approval state, effective start/end, owner, and source-health state.
Not needed
Unrelated personal profile details, unrelated accounts, or communication content.
Evidence category
Session and service records
Owner
Service evidence owner
Source health
Conditional
Minimum necessary
Account reference, service reference, session state, event time, processing time, result, and source health.
Not needed
All activity from every service or the fictional account's entire history.
Evidence category
Application workflow records
Owner
Application owner
Source health
Degraded
Minimum necessary
Workflow reference, event type, result, time, account reference if available, and limitation.
Not needed
Unrelated application content, unrelated records, or personal messages.
Evidence category
Source-health and coverage records
Owner
Source owner
Source health
Blind
Minimum necessary
Coverage period, Blind interval, recovery state, expected events, owner, and next validation.
Not needed
Broad system internals or operational configuration details.
Fake Log Panel
14:03 | REQUEST | owner=service-owner | question=account-event-during-support-window | authority=approved | scope_version=1 14:07 | EVIDENCE | category=identity-approval | source_health=Healthy | purpose=authorization-question | status=in-scope 14:11 | EVIDENCE | category=service-session | source_health=Conditional | purpose=activity-question | status=in-scope 14:14 | RECORD | category=personal-message | purpose_match=no | privacy=high | status=excluded 14:18 | CORRELATION | second_identity=observed | relationship=unconfirmed | status=scope-change-candidate 14:23 | SOURCE | workflow-records=Degraded | absence_conclusion=not-supported | owner=application-owner 14:28 | DECISION | time_window_change=requested | reason=related-event-precedes-start-by-12m | approval=pending
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
Source Health and Scope
Source health is not only a later analysis concern. It affects investigation design. If a required source is Blind, the team may need to narrow the question, preserve Unknown, request another evidence category, wait for source recovery, or change the decision timeline. A Blind source does not automatically justify collecting broader unrelated evidence.
The source is sufficiently available, current, traceable, and suitable for the specific fictional conclusion.
The source may support limited conclusions if its known limitation is preserved.
The source provides incomplete, delayed, inconsistent, or otherwise weakened evidence.
The source cannot support a reliable confirmation or absence conclusion for the relevant period.
The source disagrees materially with another traceable source or with itself and requires reconciliation.
The source is returning to service, but historical gaps or validation needs still affect conclusions.
Scope Change
New evidence can legitimately change an investigation. The control is not “never expand.” The control is “expand deliberately.” A professional scope change should preserve why the change was proposed, what evidence triggered it, how it affects privacy and workload, who owns the decision, which new items become reviewable, what remains excluded, and when the new version takes effect.
Trigger
A related fictional record predates the current start time by twelve minutes.
Weak response
Silently widen the time range and continue.
Professional response
Document the evidence trigger, explain the decision need, assess privacy effect, request the bounded time-window change, obtain owner approval, and version the scope.
Trigger
A second fictional identity appears in one correlation record.
Weak response
Add the identity automatically because it is technically related.
Professional response
Classify it as Unknown or a scope-change candidate until relationship strength, purpose, privacy, ownership, and evidence need justify expansion.
Trigger
A supplier may hold one record that could resolve a timing conflict.
Weak response
Request every record the supplier has about the service.
Professional response
Define one bounded question, minimum necessary fields, period, confidentiality level, supplier owner, deadline, and escalation path.
Trigger
A supplied fictional artifact includes unrelated personal information.
Weak response
Review it because the artifact is already available.
Professional response
Keep unrelated content excluded, use only the approved evidentiary portion, document the privacy issue, and escalate only if broader use becomes necessary.
Scenario Decision Lab
Northbridge's fictional review asks whether Account A performed an unusual action during one approved support window. A supplied correlation record references Account B at a similar time. The relationship between the accounts is not established, and no owner has requested review of Account B.
Privacy and Minimization
A supplied fictional artifact may contain both relevant and irrelevant information. Professional handling asks whether the entire artifact is necessary, whether only specific fields are needed, whether unrelated content should remain excluded, whether a privacy reviewer is required, and whether the same decision can be reached with less information.
What decision requires this specific fictional information?
Can the question be answered without the unrelated or sensitive portion?
Which fictional roles genuinely need to see the relevant portion?
How long is the information needed for the approved purpose and follow-up?
Which audience needs the finding versus the underlying evidence?
Can the learning objective be demonstrated using fully invented material instead?
Attribution Limits
A forensic scope can become unfair when the name of a person enters the question too early. A fictional record may identify an account, device, session, application, or service object. That can support an observation about the object. It may not establish who physically performed the action, whether the action was automated, whether a session was shared, whether a delegated role was active, or why the event occurred.
| Supplied Evidence | May Support | Does Not Automatically Prove | Next Question |
|---|---|---|---|
| Account event | An event was associated with the fictional account reference. | Which person acted, harmful intent, compromise, or impact. | What identity, session, approval, device, and owner context is necessary? |
| Device event | A fictional device recorded or was associated with an event. | Which person used it, who initiated the event, or why. | Is the device shared, automated, remotely managed, or used by multiple approved roles? |
| Session record | A fictional session existed or changed state. | Who physically controlled it or whether every action was authorized. | What account, approval, session-age, and service context exists? |
| Application record | A fictional application observed a defined event. | Complete user behavior, causation, intent, or system-wide impact. | Which related evidence categories are necessary for the bounded question? |
Analyze the Evidence
Stop Conditions
Stop conditions prevent momentum from becoming permission. A fictional investigation should pause or escalate when the next action would exceed the approved purpose, require new evidence access, expose sensitive information, cross into another owner's system, create a new investigative question, or rely on evidence that is too weak for the decision.
Scenario Decision Lab
A supplied fictional export contains one service-status field that may help the approved question and a long personal message unrelated to the investigation. The personal content includes information the current investigation does not need.
Common Mistakes
Why it fails
A question like ‘who did this?’ can bias evidence selection before event, account, identity, timing, and source-health questions are resolved.
Professional correction
Start with the observed fictional event and decision need.
Why it fails
A related account, device, supplier, service, or communication may be technically connected but unnecessary for the approved question.
Professional correction
Require purpose, evidence need, relationship strength, ownership, privacy, and approval.
Why it fails
A tool may technically expose many records, but interface availability is not an authorization model.
Professional correction
Use the written fictional charter, not the size of the available dataset.
Why it fails
A team can gradually widen time, systems, identities, or evidence categories without realizing the original investigation changed.
Professional correction
Version every material fictional scope change.
Why it fails
No visible event in an unavailable or incomplete source is not reliable evidence of absence.
Professional correction
Use Unknown, source-limited language, alternate evidence, or source recovery.
Why it fails
Shared devices, automation, stale sessions, delegated access, and other conditions may weaken person-level attribution.
Professional correction
State the exact object association the evidence supports.
Why it fails
Excess fictional evidence increases privacy, retention, access, review, contradiction, and lifecycle risk.
Professional correction
Use minimum necessary evidence and purpose-based retention.
Why it fails
Some fictional investigations may close with accepted Unknowns, open actions, source gaps, or future reopening conditions.
Professional correction
Document what is resolved, what is not, who owns it, and what would reopen the review.
Safe Fictional Lab
Use only the fictional Northbridge material supplied on this page. Do not access, collect, inspect, search, image, capture, extract, recover, preserve, or analyze anything from a real device, account, service, application, storage system, network, website, organization, classmate, teacher, family member, or other real person.
Lab boundary
This activity is a writing and reasoning exercise using invented supplied records only. It does not authorize real investigation, monitoring, collection, preservation, imaging, capture, extraction, recovery, account access, device access, storage access, network access, configuration changes, or technical testing.
Advanced Challenge
A fictional leadership reviewer argues that the team should include every technically related account, message, service, and device because “more evidence can only help.” Your challenge is to write a professional response explaining why disciplined minimization can improve forensic quality.
Closure Readiness
Criterion 1
The primary fictional forensic question has an evidence-supported answer or an explicitly accepted Unknown state.
Criterion 2
Every material finding identifies supporting evidence, source health, confidence, limitations, alternatives, contradictions, and unresolved questions.
Criterion 3
Scope changes and exclusions are documented with owner decisions and effective times.
Criterion 4
Unrelated or unnecessary fictional information is not retained or distributed beyond the approved purpose.
Criterion 5
Outstanding owner questions, source-recovery needs, corrective actions, or follow-up reviews have named owners and deadlines.
Criterion 6
The report has appropriate technical, privacy, service, governance, and leadership review where required.
Criterion 7
Retention, disposition, distribution, correction, archive, and reopening criteria are documented.
Criterion 8
A public CyberShield portfolio version is fully fictional and contains no real case material.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fully fictional A8.1 Forensic Investigation Charter for Northbridge. Include one neutral primary forensic question, three bounded subquestions, the decision need, requesting owner, decision owner, investigation coordinator, evidence owners, privacy reviewer, qualified governance reviewer, purpose, systems, identities, services, approved time range, evidence categories, source-health expectations, minimum-necessary fields, excluded data, unrelated-information rule, recipients, access model, retention concept, stop conditions, scope states, one Unknown item, one excluded item, one scope-change candidate, scope-change approval workflow, attribution limits, non-proof statements, five alternative explanations, open owner questions, closure criteria, reopen triggers, and a statement that every organization, identity, account, device, service, source, record, date, event, decision, and outcome is invented.
Confidence / Readiness Reflection
Rate your readiness from 1 to 5 for neutral forensic questions, purpose limitation, authority, scope states, minimization, source health, attribution limits, scope change, privacy, stop conditions, closure, and public-safe fictionalization.
Key Takeaways
Safety Boundary
Nothing in A8.1 authorizes access, investigation, monitoring, collection, preservation, imaging, memory capture, extraction, credential recovery, packet capture, live acquisition, storage access, account access, private-message review, configuration changes, recovery actions, surveillance, or examination involving any real device, account, application, service, storage system, network, organization, incident, classmate, teacher, family member, or other person. Use only fully invented supplied evidence.
Lesson Complete
A8.1 defined what the investigation is allowed to ask and review. A8.2 moves to the next professional question: once a fictional evidence item is in scope, how do defenders document its identity, provenance, handling, access, transfer, integrity, retention, correction, and limitations?