WGU C840 DIGITAL FORENSICS PRACTICE
EXAMINATION 2026 QUESTIONS WITH
ANSWERS GRADED A+
◍ The National Institute of Standards and Technology (NIST) guidelines list
four different states a mobile device can be in when you extract data. The
__________ mode is a dormant mode that conserves battery life while
maintaining user data and performing other background functions..
Answer: quiescent
◍ ISO9660.
Answer: A file system used with CDs.
◍ You can undelete files in Macintosh..
Answer: TRUE
◍ test system.
Answer: A functional system compatible with the hard drive from which
someone is trying to recover data.
◍ Federal Rules of Evidence (FRE).
Answer: The Federal Rules of Evidence (FRE) is a code of evidence law.
The FRE governs the admission of facts by which parties in the U.S. federal
court system may prove their cases. The rules of evidence, encompasses the
rules and legal principles that govern the proof of facts in a legal
proceeding. These rules determine what evidence must or must not be
considered by the trier of fact in reaching its decision
◍ A test system is a functional system compatible with the system from which
a hard drive was removed for the purpose of trying to recover data..
Answer: TRUE
,◍ Physical analysis.
Answer: Offline analysis conducted on an evidence disk or forensic
duplicate after booting from a CD or another system.
◍ Atbash.
Answer: Hebrew scribes copying the book of Jeremiah used the Atbash
cipher. This cipher is very simple and simply reverses the alphabet. This is,
by modern standards, a very primitive and easy-to-break cipher. However, it
helps one get a feel for how cryptography works.
◍ Logical damage.
Answer: Damage to how the data is stored—for example, file system
corruption.
◍ __________ is a commonly used name for a command-line utility that
provides disk partitioning functions in an operating system. It can list the
partitions on a Linux system..
Answer: fdisk
◍ ______ is an asymmetric cryptography algorithm invented by three
mathematicians in the 1970s?.
Answer: RSA
◍ The __________ is a central controller coordinating the other pieces of the
BSS..
Answer: base station controller (BSC)
◍ In 1986, the _________ was released; this computer was 16-bit rather than
8-bit..
Answer: Apple IIGS
◍ __________ is a Linux Live CD that you use to boot a system and then use
the tools. It is a free Linux distribution, making it extremely attractive to
schools teaching forensics or laboratories on a strict budget..
Answer: BackTrack
◍ IXimager.
, Answer: developed by the IRS and restricted to law enforcement and
government use
◍ /Library/Receipts folder.
Answer: The /Library/Receipts folder contains information about system
and software updates. It is less useful for a forensic investigation than some
of the other folders; however, it can be useful to know if a given patch was
applied and when it was applied. This might be of some interest in
investigating malware crimes.
◍ hierarchical storage management (HSM).
Answer: Continuous online backup storage.
◍ This is the space that remains on a hard drive if the partitions do not use all
the available space..
Answer: volume slack
◍ China Eagle Union.
Answer: The cyberterrorism group, the China Eagle Union, consists of
several thousand Chinese hackers whose stated goal is to infiltrate Western
computer systems. Members and leaders of the group insist that not only
does the Chinese government have no involvement in their activities, but
that they are breaking Chinese law and are in constant danger of arrest and
imprisonment. However, most analysts believe this group is working with
the full knowledge and support of the Chinese government.
◍ keyspace.
Answer: The total number of keys.
◍ EnCase eDiscovery.
Answer: EnCase eDiscovery performs the search, collection, preservation,
and processing in a forensically sound manner. It collects and processes
only potentially relevant data.
◍ The Windows Registry is organized into five sections. The __________
section contains those settings common to the entire machine, regardless of
the individual user..
, Answer: HKEY_LOCAL_MACHINE (HKLM)
◍ carrier.
Answer: The signal, stream, or data file into which the payload is hidden.
◍ Heap (H).
Answer: Dynamic memory for a program comes from the heap segment. A
process may use a memory allocator such as malloc to request dynamic
memory.
◍ The subscriber identity module (SIM) is a memory chip that stores the
__________..
Answer: international mobile subscriber identity (IMSI)
◍ FIN bit.
Answer: The FIN bit indicates that there is no more data from the sender.
◍ Consistency checking.
Answer: A technique for file system repair that involves scanning a disk's
logical structure and ensuring that it is consistent with its specification.
◍ NSF File Format.
Answer: Lotus Notes uses the NSF file format.
◍ You need to image a server that is set up with RAID 5. How would you
approach this?.
Answer: Image each disk separately.
◍ Linux offers many different shells. Each shell is designed for a different
purpose. __________ is the most commonly used shell in Linux..
Answer: Bourne-again shell
◍ Transposition.
Answer: In terms of cryptography, this is the swapping of blocks of
ciphertext.
◍ Which software forensic tool offers Blade, HstEx, and NetAnalysis?.
Answer: Digital Detective offers Blade, HstEx, and NetAnalysis. Blade is a
Windows-based data recovery solution. It supports plug-ins that give it
EXAMINATION 2026 QUESTIONS WITH
ANSWERS GRADED A+
◍ The National Institute of Standards and Technology (NIST) guidelines list
four different states a mobile device can be in when you extract data. The
__________ mode is a dormant mode that conserves battery life while
maintaining user data and performing other background functions..
Answer: quiescent
◍ ISO9660.
Answer: A file system used with CDs.
◍ You can undelete files in Macintosh..
Answer: TRUE
◍ test system.
Answer: A functional system compatible with the hard drive from which
someone is trying to recover data.
◍ Federal Rules of Evidence (FRE).
Answer: The Federal Rules of Evidence (FRE) is a code of evidence law.
The FRE governs the admission of facts by which parties in the U.S. federal
court system may prove their cases. The rules of evidence, encompasses the
rules and legal principles that govern the proof of facts in a legal
proceeding. These rules determine what evidence must or must not be
considered by the trier of fact in reaching its decision
◍ A test system is a functional system compatible with the system from which
a hard drive was removed for the purpose of trying to recover data..
Answer: TRUE
,◍ Physical analysis.
Answer: Offline analysis conducted on an evidence disk or forensic
duplicate after booting from a CD or another system.
◍ Atbash.
Answer: Hebrew scribes copying the book of Jeremiah used the Atbash
cipher. This cipher is very simple and simply reverses the alphabet. This is,
by modern standards, a very primitive and easy-to-break cipher. However, it
helps one get a feel for how cryptography works.
◍ Logical damage.
Answer: Damage to how the data is stored—for example, file system
corruption.
◍ __________ is a commonly used name for a command-line utility that
provides disk partitioning functions in an operating system. It can list the
partitions on a Linux system..
Answer: fdisk
◍ ______ is an asymmetric cryptography algorithm invented by three
mathematicians in the 1970s?.
Answer: RSA
◍ The __________ is a central controller coordinating the other pieces of the
BSS..
Answer: base station controller (BSC)
◍ In 1986, the _________ was released; this computer was 16-bit rather than
8-bit..
Answer: Apple IIGS
◍ __________ is a Linux Live CD that you use to boot a system and then use
the tools. It is a free Linux distribution, making it extremely attractive to
schools teaching forensics or laboratories on a strict budget..
Answer: BackTrack
◍ IXimager.
, Answer: developed by the IRS and restricted to law enforcement and
government use
◍ /Library/Receipts folder.
Answer: The /Library/Receipts folder contains information about system
and software updates. It is less useful for a forensic investigation than some
of the other folders; however, it can be useful to know if a given patch was
applied and when it was applied. This might be of some interest in
investigating malware crimes.
◍ hierarchical storage management (HSM).
Answer: Continuous online backup storage.
◍ This is the space that remains on a hard drive if the partitions do not use all
the available space..
Answer: volume slack
◍ China Eagle Union.
Answer: The cyberterrorism group, the China Eagle Union, consists of
several thousand Chinese hackers whose stated goal is to infiltrate Western
computer systems. Members and leaders of the group insist that not only
does the Chinese government have no involvement in their activities, but
that they are breaking Chinese law and are in constant danger of arrest and
imprisonment. However, most analysts believe this group is working with
the full knowledge and support of the Chinese government.
◍ keyspace.
Answer: The total number of keys.
◍ EnCase eDiscovery.
Answer: EnCase eDiscovery performs the search, collection, preservation,
and processing in a forensically sound manner. It collects and processes
only potentially relevant data.
◍ The Windows Registry is organized into five sections. The __________
section contains those settings common to the entire machine, regardless of
the individual user..
, Answer: HKEY_LOCAL_MACHINE (HKLM)
◍ carrier.
Answer: The signal, stream, or data file into which the payload is hidden.
◍ Heap (H).
Answer: Dynamic memory for a program comes from the heap segment. A
process may use a memory allocator such as malloc to request dynamic
memory.
◍ The subscriber identity module (SIM) is a memory chip that stores the
__________..
Answer: international mobile subscriber identity (IMSI)
◍ FIN bit.
Answer: The FIN bit indicates that there is no more data from the sender.
◍ Consistency checking.
Answer: A technique for file system repair that involves scanning a disk's
logical structure and ensuring that it is consistent with its specification.
◍ NSF File Format.
Answer: Lotus Notes uses the NSF file format.
◍ You need to image a server that is set up with RAID 5. How would you
approach this?.
Answer: Image each disk separately.
◍ Linux offers many different shells. Each shell is designed for a different
purpose. __________ is the most commonly used shell in Linux..
Answer: Bourne-again shell
◍ Transposition.
Answer: In terms of cryptography, this is the swapping of blocks of
ciphertext.
◍ Which software forensic tool offers Blade, HstEx, and NetAnalysis?.
Answer: Digital Detective offers Blade, HstEx, and NetAnalysis. Blade is a
Windows-based data recovery solution. It supports plug-ins that give it