WGU C702 PROFESSIONAL EXAM
COLLECTION 2026 COMPLETE QUESTIONS
AND ANSWERS DETAILED STUDY PACK
GRADED A+
⩥ Which model or legislation applies a holistic approach toward any
criminal activity as a criminal operation?
Enterprise Theory of Investigation
Racketeer Influenced and Corrupt Organizations Act
Evidence Examination
Law Enforcement Cyber Incident Reporting.
Answer: Enterprise Theory of Investigation
⩥ What does a forensic investigator need to obtain before seizing a
computing device in a criminal case?
Court warrant
Completed crime report
Chain of custody document
Plaintiff's permission.
Answer: Court warrant
,⩥ Which activity should be used to check whether an application has
ever been installed on a computer?
Penetration test
Risk analysis
Log review
Security review.
Answer: Log review
⩥ Which characteristic describes an organization's forensic readiness in
the context of cybercrimes?
It includes moral considerations.
It includes cost considerations.
It excludes nontechnical actions.
It excludes technical actions..
Answer: It includes cost considerations.
⩥ A cybercrime investigator identifies a Universal Serial Bus (USB)
memory stick containing emails as a primary piece of evidence.
, Who must sign the chain of custody document once the USB stick is in
evidence?
Those who obtain access to the device
Anyone who has ever used the device
Recipients of emails on the device
Authors of emails on the device.
Answer: Those who obtain access to the device
⩥ Which type of attack is a denial-of-service technique that sends a large
amount of data to overwhelm system resources?
Phishing
Spamming
Mail bombing
Bluejacking.
Answer: Mail bombing
⩥ Which computer crime forensics step requires an investigator to
duplicate and image the collected digital information?
Securing evidence
Acquiring data
COLLECTION 2026 COMPLETE QUESTIONS
AND ANSWERS DETAILED STUDY PACK
GRADED A+
⩥ Which model or legislation applies a holistic approach toward any
criminal activity as a criminal operation?
Enterprise Theory of Investigation
Racketeer Influenced and Corrupt Organizations Act
Evidence Examination
Law Enforcement Cyber Incident Reporting.
Answer: Enterprise Theory of Investigation
⩥ What does a forensic investigator need to obtain before seizing a
computing device in a criminal case?
Court warrant
Completed crime report
Chain of custody document
Plaintiff's permission.
Answer: Court warrant
,⩥ Which activity should be used to check whether an application has
ever been installed on a computer?
Penetration test
Risk analysis
Log review
Security review.
Answer: Log review
⩥ Which characteristic describes an organization's forensic readiness in
the context of cybercrimes?
It includes moral considerations.
It includes cost considerations.
It excludes nontechnical actions.
It excludes technical actions..
Answer: It includes cost considerations.
⩥ A cybercrime investigator identifies a Universal Serial Bus (USB)
memory stick containing emails as a primary piece of evidence.
, Who must sign the chain of custody document once the USB stick is in
evidence?
Those who obtain access to the device
Anyone who has ever used the device
Recipients of emails on the device
Authors of emails on the device.
Answer: Those who obtain access to the device
⩥ Which type of attack is a denial-of-service technique that sends a large
amount of data to overwhelm system resources?
Phishing
Spamming
Mail bombing
Bluejacking.
Answer: Mail bombing
⩥ Which computer crime forensics step requires an investigator to
duplicate and image the collected digital information?
Securing evidence
Acquiring data