ACC 693 Module 5 Forensic Imaging Assignment Example

Reviewed by Portia Lambrick, MBA

This ACC 693 Module 5 Forensic Imaging Assignment sample documents how a laptop and a phone were acquired so that the evidence on them can be relied on later. SNHU ACC 693 (ACC-693) gives MS Accounting students this acquisition task in Module Five. At a composite Colorado roofing contractor, an outside forensic firm imaged a project manager's encrypted company laptop while he was at a job site, and a week later he consented to a limited extraction from his personal phone. The paper explains each step, from write blocking and hashing to unlocking the encrypted drive, discusses what solid-state storage means for deleted files, describes the narrow phone extraction and shows the documentation that supports both acquisitions.

CourseACC 693 Investigating with Computers
ModuleModule 5
Paper typegraduate assignment documenting forensic acquisition of a laptop and a phone
LengthAbout 1,090 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Accounting
UpdatedOctober 2026

Free sample paper for ACC 693 Module 5

1

Forensic Acquisition of the Project Manager's Laptop and Phone

[Student Name]

Southern New Hampshire University

ACC 693: Investigating with Computers

Module Five Assignment

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title names both devices and whose they are.
2

Forensic Acquisition of the Project Manager's Laptop and Phone

Introduction

This paper documents the acquisition of two devices in the investigation of a sham flashing subcontractor at a Colorado roofing contractor. The first is the senior project manager's company laptop, imaged on day five of the evidence plan while he attended a job-site meeting. The second is his personally owned phone, from which a limited extraction was made a week later with his written consent. Both acquisitions were carried out by an outside forensic firm retained by the company's general counsel, with the internal auditor present as a witness. For each, the paper describes the procedure, the verification of integrity, the issues specific to the device and the documentation produced.

What this page is doingThe two acquisitions are introduced.
3

The Laptop: Preparation

At 9:40 a.m. on day five, the IT director retrieved the laptop from the project manager's office and handed it to the forensic examiner in a conference room. The examiner photographed the laptop on all sides, recorded the make, model, serial number and asset tag, noted that it was powered off and that no external media were attached, and began an acquisition worksheet. Kent et al. (2006) recommend this documentation before any acquisition because it establishes the state of the device when it was received. The laptop's 512-gigabyte NVMe solid-state drive was removed and its serial number photographed.

What this page is doingThe device is documented before it is touched.
4

The Laptop: Imaging and Verification

The drive was connected to the forensic workstation through a hardware write blocker designed for NVMe drives, which allows reading but blocks any write command. The examiner confirmed that the blocker reported write protection active before connecting it to the workstation. A full physical image was made in the E01 evidence format, which stores the data with case information and internal checksums. The imaging software computed a SHA-256 hash value of the source drive during acquisition and a second value of the completed image.

Laptop acquisition record

ItemDetail
DeviceCompany laptop, 512 GB NVMe solid-state drive
Write protectionHardware write blocker, protection confirmed before connection
Image formatE01, compressed, segmented in 2 GB files
Start and finish9:58 a.m. to 11:21 a.m.
Source hash, SHA-256Recorded on worksheet, first eight characters 4f9a21c7
Image hash, SHA-256Recorded on worksheet, first eight characters 4f9a21c7
VerificationValues identical; image verified again at the lab

The drive was reinstalled, the laptop powered on to confirm it worked and returned to the office at 11:40 a.m. Two copies of the image were made at the forensic firm's lab, each verified against the original hash. One copy is held as the reference and is never opened for analysis; the second is the working copy. Any opposing expert can be given a further verified copy of the reference image and can repeat the examination independently, which is the practical meaning of forensic soundness. The worksheet also records the firmware version of the write blocker and the version of the imaging software, since a challenge to a tool is easier to answer when its exact version is known and its validation testing can be produced.

What this page is doingThe copy is proved exact.
5

The Laptop: Encryption

The drive was protected by BitLocker full-disk encryption, so the raw image could not be read without a key. The company's device management system escrows each laptop's recovery key, and the IT director retrieved this laptop's key under the general counsel's written authorization. The examiner entered the key into the forensic software, which decrypts the image as it is read without modifying the image file itself. Retrieval of the key was logged in the device management system and recorded on the worksheet, so its use can be shown later.

What this page is doingThe drive is unlocked without changing it.
6

The Laptop: Limits of Recovery

Solid-state drives handle deletion differently from older hard drives. When a file is deleted, the operating system sends a TRIM command telling the drive that the blocks are no longer needed, and the drive may erase them in the background. Bell and Boddington (2010) showed that this process can destroy deleted data within minutes, so traditional recovery of deleted files from unallocated space is unreliable on these drives. The examination will therefore rely more on artifacts that survive deletion, such as shortcut files, jump lists, the Windows registry, application logs and copies of files synchronized to OneDrive, which was collected separately on day three. This limit is stated in the report rather than discovered by the defense. It cuts both ways: the absence of a deleted file on the image does not show that the file never existed, and the report must not imply otherwise.

What this page is doingSolid-state storage affects deleted files.
7

The Phone: Scope of Consent

On day twelve, during his interview, the project manager agreed to let the company review text messages with three named contacts: his brother-in-law and two crew foremen. The consent form he signed lists those contacts, the period from January 2023 to May 2025, the types of data, text and iMessage conversations and call history with those numbers, and states that other data will not be reviewed and that he may withdraw consent before the extraction begins. Casey (2011) stresses that the authority for a search sets its limits, and exceeding consent can make evidence inadmissible and expose the company to liability.

What this page is doingConsent defines what is collected.
8

The Phone: Extraction

The examiner photographed the phone, recorded its model and serial number, placed it in airplane mode to prevent remote changes and connected it to a forensic extraction tool with the project manager's passcode, which he entered himself. A logical extraction of messages and call logs was made, and the tool's filter limited the exported report to the three numbers and the consented period. The full extraction file, needed to show the filtered report's source, was hashed and sealed without review. The exported report and its hash were recorded on a second worksheet, and the phone was returned to him within forty minutes.

What this page is doingA filtered logical extraction.
9

Chain of Custody

Both acquisitions were recorded on the firm's custody forms: the laptop drive from the IT director to the examiner and back; the images from the examiner to the lab; the phone extraction file to sealed storage; and the filtered report to the analysis team. Each entry lists date, time, persons, purpose and hash value.

What this page is doingEvery handoff is recorded.
10

Conclusion

The laptop image is an exact, verified copy of an encrypted solid-state drive, unlocked with an escrowed key whose use is logged, and its limits for deleted data are documented. The phone extraction stayed within a written consent limited to three contacts, and the unfiltered extraction file remains sealed unless he later broadens his consent or a court orders its review. Together, the documentation lets a court or opposing expert confirm what was collected, how and by whom.

What this page is doingThe acquisitions are summarized.
11

References

Bell, G. B., & Boddington, R. (2010). Solid state drives: The beginning of the end for current practice in digital forensic recovery? Journal of Digital Forensics, Security and Law, 5(3), 1-20. https://doi.org/10.15394/jdfsl.2010.1078

Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the Internet (3rd ed.). Academic Press.

Kent, K., Chevalier, S., Grance, T., & Dang, H. (2006). Guide to integrating forensic techniques into incident response (NIST Special Publication 800-86). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-86

What the ACC 693 Module 5 instructions ask for

The Module Five assignment in ACC 693 asks you to describe how digital evidence is acquired in a forensically sound way, usually for a computer and sometimes a phone or cloud account. You explain the tools and steps, including write protection, imaging format, hash verification and handling of encryption, and you document the acquisition so that someone else could confirm it. Many versions also ask about limits, such as what an image of a solid-state drive can and cannot recover, or how consent defines the scope of a phone extraction. Graders want specific procedures, not general statements that evidence was preserved, and they expect the documentation to be part of the answer.

How this ACC 693 Module 5 forensic imaging assignment example is built

The paper describes the laptop acquisition on day five: photographs of the device and its serial number, removal of the NVMe drive, connection through a hardware write blocker, a full physical image in E01 format and verification by matching SHA-256 values computed at acquisition and again afterward. Because the drive was encrypted with BitLocker, the company's escrowed recovery key was used inside the forensic tool to read the image without altering it. The paper explains that TRIM on solid-state drives may have erased deleted files, then turns to the phone, where the project manager signed a consent limited to messages with three contacts from 2023 to 2025, and a filtered logical extraction was made.

Where the ACC 693 Module 5 rubric puts the points

The rubric for this assignment typically scores the acquisition procedure, write protection and integrity verification, handling of encryption and device-specific issues, scope and legal authority, documentation and chain of custody, and writing. Top papers state the tools and formats used, show the hash values matching, explain why each step protects the evidence and address the limits honestly, such as the effect of solid-state storage on deleted data. They also tie the phone extraction to the scope of consent and describe how data outside that scope was handled. Papers lose credit for vague descriptions, for omitting verification, for ignoring encryption and for collecting more from a personal device than the consent allowed.

ACC 693 Module 5 help: the mistakes that cost points

The commonest gap in acquisition papers is verification: students say a drive was imaged but never show that the image matches the source. Report both hash values and state when each was computed. Encryption is another frequent omission; a modern laptop is usually encrypted, so explain how the key was obtained and used. Be careful with personal devices: the consent form defines the scope, and the extraction should be filtered to it, with anything outside the scope not reviewed. Include the paperwork, such as the acquisition worksheet and custody form, because the documentation is what lets the evidence be used, and name who witnessed each step.

Get ACC 693 Module 5 written to your instructions

Send the ACC 693 Module 5 assignment and the devices in your scenario. The paper will set out each acquisition step, hashing and verification, encryption handling, scope limits and the paperwork that proves integrity. You should have it in about two days; first papers are written free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More ACC 693 papers and related MS Accounting samples

ACC 693 Module 5 questions, answered

Where can I find a free ACC 693 Module 5 Forensic Imaging sample?

This page includes a complete ACC 693 Module 5 assignment documenting a write-blocked laptop image and a consent-limited phone extraction.

What is a write blocker?

A small piece of equipment, or sometimes a program, placed between the evidence drive and the examiner's computer; it passes reads through and refuses every write, so copying cannot change the original.

Why are hash values used in forensic imaging?

A hash value is a fixed-length fingerprint of the data; if the hash of the image matches the hash of the source, the copy is exact, and any later change would produce a different value.

How does encryption affect forensic imaging?

An encrypted drive can be imaged, but its contents cannot be read without the key; organizations often escrow recovery keys, which allows authorized examiners to decrypt the image.

Why is recovering deleted files harder on solid-state drives?

Solid-state drives use commands such as TRIM that tell the drive to erase blocks no longer in use, so deleted data may be gone by the time the drive is imaged.