AND CORRECT ANSWERS WITH RATIONALE LATEST
UPDATE ALREADY GRADED A+ ASSURED PASS
This comprehensive 300-question exam bank for the WGU C702 Forensics and
Network Intrusion final OA is meticulously structured according to official
course competencies, aligned with the EC-Council CHFI certification objectives.
It covers the complete digital forensics investigation process across all key
domains: investigation methodology, evidence collection and preservation,
incident response, file systems, network forensics, operating system forensics,
malware analysis, mobile and cloud forensics, anti-forensics, legal and ethical
standards, and forensic tools. Each question presents a realistic forensic
scenario requiring application of core principles and critical thinking. Every entry
includes four multiple-choice options, one correct answer, and a detailed
evidence-based rationale explaining the underlying forensic principle. This
resource is ideal for self-assessment, remediation, and thorough preparation for
the WGU C702 OA exam.
Domain 1: Digital Forensics Fundamentals and Investigation Methodology
This domain covers computer forensics definition, cybercrime types, investigation
steps, Locard's Exchange Principle, enterprise theory of investigation, and rules of
forensic investigation.
Question 1
Which of the following best defines computer forensics?
A) The process of preventing cyber attacks on organizational networks
,B) A set of methodological procedures and techniques that help identify, gather,
preserve, extract, interpret, document, and present evidence from computers in a
way that is legally admissible
C) The study of how computers are manufactured and assembled
D) The process of encrypting data to protect it from unauthorized access
Answer: B
Rationale: Computer forensics is defined as a set of methodological procedures
and techniques that help identify, gather, preserve, extract, interpret, document,
and present evidence from computers in a way that is legally admissible in a court
of law . This definition emphasizes the legal admissibility requirement,
distinguishing computer forensics from general data recovery or cybersecurity.
Question 2
What is a cybercrime?
A) Any illegal act involving a computing device, network, its systems, or its
applications
B) Only crimes committed by external hackers against an organization
C) Any crime that involves physical theft of computer hardware
D) Only crimes involving financial fraud through electronic means
Answer: A
Rationale: A cybercrime is any illegal act involving a computing device, network,
its systems, or its applications . Cybercrimes can be committed by both internal
(employees) and external (hackers, criminals) actors. The definition encompasses
a wide range of illegal activities, from data theft to network intrusions.
Question 3
A software company suspects that employees have set up automatic corporate
email forwarding to their personal inboxes against company policy. The company
hires forensic investigators to identify the employees violating policy, with the
intention of issuing warnings. Which type of cybercrime investigation approach is
this company taking?
A) Civil
B) Criminal
,C) Administrative
D) Punitive
Answer: C
Rationale: This is an administrative case, which is an internal investigation by an
organization to discover if its employees, clients, or partners are abiding by the
rules or policies . Administrative cases are non-criminal in nature and are related
to misconduct or activities of an employee. Civil cases involve disputes between
two parties with monetary damages, and criminal cases are brought by law
enforcement agencies .
Question 4
What is the first step in the cybercrime investigation methodology?
A) Create two bitstream copies of the evidence
B) Identify the computer crime
C) Perform first responder procedures
D) Analyze the image copy for evidence
Answer: B
Rationale: The first step in the cybercrime investigation methodology is to identify
the computer crime . This initial identification sets the direction for the entire
investigation. Subsequent steps include collecting preliminary evidence, obtaining
court warrants, performing first responder procedures, seizing evidence, creating
bitstream copies, and analyzing evidence .
Question 5
What does Locard's Exchange Principle state?
A) Digital evidence is always volatile and must be collected quickly
B) Anyone entering a crime scene takes something of the scene with them and
leaves something of themselves behind when they leave
C) All digital evidence must be collected by law enforcement only
D) Evidence must be preserved in its original state without any duplication
Answer: B
, Rationale: Locard's Exchange Principle states that anyone entering a crime scene
takes something from the scene with them and leaves something of themselves
behind when they leave . This principle applies to both physical and digital crime
scenes and is fundamental to forensic investigations. It is the basis for the transfer
of evidence.
Question 6
What is the focus of the Enterprise Theory of Investigation (ETI)?
A) Investigating only physical crimes while ignoring digital evidence
B) Solving one crime can tie it back to a criminal organization's activities
C) Focusing solely on individual perpetrators without considering organizational
connections
D) Investigating only cybercrimes committed by nation-states
Answer: B
Rationale: The Enterprise Theory of Investigation (ETI) is a methodology for
investigating criminal activity that takes a holistic approach . The focus is that
solving one crime can tie it back to a criminal organization's activities, identifying
larger criminal enterprises rather than just individual perpetrators.
Question 7
Which type of cybercrime case involves disputes between two parties, typically
resulting in monetary damages to the plaintiff?
A) Criminal case
B) Administrative case
C) Civil case
D) Federal case
Answer: C
Rationale: Civil cases involve disputes between two parties and are brought for
violation of contracts and lawsuits where a guilty outcome generally results in
monetary damages to the plaintiff . This contrasts with criminal cases, which are
brought by law enforcement and can result in imprisonment. Administrative cases
are internal organizational investigations .