VERSION REAL EXAM QUESTIONS AND
CORRECT ANSWERS / WGU C702 EXAM
200 EXAM QUESTIONS AND ANSWERS
BRAND NEW VERSION!! 2025-2026.
______ Is a 128 bit unique reference number used as an identifier in computer
software? - ans-global unique identifier (guid).
On windows server 2012, by default, the iis log files are stored at which of
the following locations? - ans-%systemdrive%\inetpub\logs\logfiles.
Digital devices store data about session such as user and type of connection.
- ans-true.
Espionage, theft of intellectual property, manipulation of records, and trojan
horse attacks are examples of what? - ans-insider attack or primary attacks.
,External attacks occur when there are inadequate information-security
policies and procedures. - ans-true.
For forensics analysis, which of the following mysql utility programs is used
to export metadata, data, or both from one or more databases? - ans-
mysqldbexport
Forensic data duplication involves the creation of a file that has every bit of
information from the source in a raw bit-stream format. - ans-true.
________ command is used to display the network configuration of the nics on
the system. - ans-ipconfig /all
________ is the standard investigative model used by the fbi when conducting
investigations against major criminal organizations. - ans-enterprise theory of
investigation (eti).
A chain of custody is a critical document in the computer forensics
investigation process because the document provides legal validation of
appropriate evidence handling. - ans-true.
A computer forensic examiner can investigate any crime as long as he or she
takes detailed notes and follows the appropriate processes. - ans-false.
An email client connects with a pop3 server via which of the following? - ans-
port 110.
An investigator may commit some common mistakes while collecting data
from the system that result in the loss of critical evidence. Which of the
following is not a mistake that investigators commonly make? - ans-use of
correct cables and cabling techniques.
, Because they are always changing, the information in the registers or the
processor cache are the most volatile data. - ans-true.
Codes of ethics are the principles stated to describe the expected behavior
of an investigator while handling a case. Which of the following is not a
principle that a computer forensic investigator must follow? - ans-provide
personal or prejudiced opinions.
Computer forensics deals with the process of finding _____ related to a digital
crime to find the culprits and initiate legal action against them. - ans-
evidence.
Courts call knowledgable persons to testify to the accuracy of the
investigative process. These people who tesify are known as the: - ans-
expert witnesses.
Cybercrimes can be classified into the following two types of attacks, based
on the line of attack. - ans-internal and external.
Forensic readiness includes technical and nontechnical actions that
maximize an organization's competence to use digital evidence. - ans-true.
Forensic readiness refers to: - ans-an organization's ability to make optimal
use of digital evidence in a limited time period and with minimal
investigation costs.
How can an attacker exploit a network? - ans-through wired or wireless
connections.
How large is the partition table structure that stores information about the
partitions present on the hard disk? - ans-64-byte.