WGU D829 Digital Forensics exam with
correct answers and rationale
updated 2026 graded A+
1. What is the very first action you should take upon receiving the initial alert from John Doe?
A. Immediately unplug the power cord from WS-045.
B. Create a forensic image of the hard drive using FTK Imager.
C. Interview John Doe to document the symptoms and timeline of the incident.
D. Scan the network for other compromised hosts.
Correct Answer: C
Rationale: The first step in the Identification phase is to gather initial information. Interviewing the
reporter (John Doe) establishes the scope, timeline, and symptoms. Jumping to imaging or power-off
could destroy volatile data or violate chain of custody protocols without proper context.
2. Which standard primarily dictates the principles of "defensible" forensic acquisition?
A. NIST SP 800-86
B. ISO 27001
C. ISO 27037
D. PCI DSS 4.0
Correct Answer: C
Rationale: ISO 27037 specifically provides guidelines for identification, collection, acquisition, and
preservation of digital evidence in a defensible manner. NIST SP 800-86 is a guide for integrating
forensics into incident response, but ISO 27037 focuses on the forensic process itself.
3. During the Preparation phase, what is the most crucial policy element to have in place?
A. A standard email retention policy.
B. A clearly defined Chain of Custody (CoC) form.
C. A list of employee passwords.
D. A backup of all financial data.
Correct Answer: B
,Rationale: The Preparation phase requires having tools, policies, and forms ready. A Chain of
Custody form is essential for maintaining the integrity and admissibility of evidence. Email retention
and financial backups are separate compliance issues.
4. You arrive at John Doe's desk. The computer is on, showing a Windows desktop. What is the first
volatile data you MUST capture?
A. The contents of the Recycle Bin.
B. The contents of RAM (Random Access Memory).
C. The Master Boot Record (MBR).
D. The Windows Event Logs.
Correct Answer: B
Rationale: Volatile data degrades over time. RAM contains running processes, network connections,
and encryption keys. It is lost when the power is removed. Event logs and MBR are non-volatile and
stored on the hard drive.
5. You execute a memory capture tool (e.g., DumpIt) on WS-045. After capturing RAM, what should
you do immediately?
A. Run a full antivirus scan.
B. Perform a graceful shutdown via the Start Menu.
C. Remove the hard drive and connect it to a write-blocker.
D. Document the SHA-256 hash of the memory dump file.
Correct Answer: D
Rationale: Hashing the captured file (memory dump) immediately creates a digital fingerprint to
verify integrity later. After capturing volatile memory, you should perform a hard power-off (pull the
plug) to preserve the state of the hard drive, not a graceful shutdown.
6. You legally acquire the hard drive from WS-045. Before imaging, you must attach it to a write-
blocker. What is the primary purpose of a hardware write-blocker?
A. To speed up the imaging process via USB 3.0.
B. To prevent any data from being written to the source drive.
C. To decrypt BitLocker-encrypted drives automatically.
D. To sanitize the drive of malware before analysis.
Correct Answer: B
,Rationale: The cardinal rule of forensics is to never modify the original evidence. A write-blocker
ensures that the operating system cannot write metadata (like last access timestamps) to the
suspect drive.
7. You use FTK Imager to create a forensic image. Which imaging method is the most forensically
sound?
A. Logical acquisition of the C: drive only.
B. Sparse acquisition of only ".docx" files.
C. Bit-for-bit (sector-by-sector) acquisition.
D. Network acquisition over the company LAN.
Correct Answer: C
Rationale: A bit-for-bit image captures the entire storage medium, including slack space, unallocated
clusters, and deleted files. Logical and sparse acquisitions miss critical hidden data.
8. During imaging, FTK Imager generates a hash. Which hash algorithm is currently the industry
standard for forensic verification?
A. MD5
B. SHA-1
C. SHA-256
D. CRC32
Correct Answer: C
Rationale: While MD5 and SHA-1 are still used, SHA-256 is considered more cryptographically secure
and is the current NIST-recommended standard for forensic integrity. CRC32 is for error detection,
not forensic validation.
9. You analyze the image in Autopsy/Sleuth Kit. You find a file with a "Zone.Identifier" alternate data
stream (ADS). What does this indicate?
A. The file was created locally by John Doe.
B. The file was downloaded from the internet (e.g., a browser).
C. The file is a system file protected by Windows.
D. The file is encrypted with EFS.
Correct Answer: B
, Rationale: A "Zone.Identifier" ADS is added by Windows when a file is downloaded from the
internet. It contains a "ZoneId" (e.g., ZoneId=3 for Internet). This is crucial for tracing the origin of
malware or exfiltrated data.
10. In the Windows Registry, what hive is most critical for identifying programs set to run at system
startup?
A. SAM
B. SECURITY
C. SYSTEM
D. NTUSER.DAT
Correct Answer: D
Rationale: NTUSER.DAT contains the HKEY_CURRENT_USER hive for a specific user (John Doe). The
"Run" and "RunOnce" keys reside here and in
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
11. You review the Windows Security Event Log (Event ID 4624). What does this event specifically
track?
A. Failed logon attempts.
B. Successful logon attempts.
C. Process creation.
D. File deletion.
Correct Answer: B
Rationale: Event ID 4624 is "An account was successfully logged on." Event ID 4625 tracks failed
logons. This helps identify if John Doe was logged in at the time of exfiltration.
12. Your analysis reveals that malware connected to an external IP address 185.xxx.xx.5. What is this
data point called?
A. A file hash (IOC)
B. A network indicator (IOC)
C. A behavioral signature
D. A threat vector
Correct Answer: B
Rationale: An Indicator of Compromise (IOC) is evidence of a breach. IP addresses, domain names,
and URLs are classified as network-based IOCs.
correct answers and rationale
updated 2026 graded A+
1. What is the very first action you should take upon receiving the initial alert from John Doe?
A. Immediately unplug the power cord from WS-045.
B. Create a forensic image of the hard drive using FTK Imager.
C. Interview John Doe to document the symptoms and timeline of the incident.
D. Scan the network for other compromised hosts.
Correct Answer: C
Rationale: The first step in the Identification phase is to gather initial information. Interviewing the
reporter (John Doe) establishes the scope, timeline, and symptoms. Jumping to imaging or power-off
could destroy volatile data or violate chain of custody protocols without proper context.
2. Which standard primarily dictates the principles of "defensible" forensic acquisition?
A. NIST SP 800-86
B. ISO 27001
C. ISO 27037
D. PCI DSS 4.0
Correct Answer: C
Rationale: ISO 27037 specifically provides guidelines for identification, collection, acquisition, and
preservation of digital evidence in a defensible manner. NIST SP 800-86 is a guide for integrating
forensics into incident response, but ISO 27037 focuses on the forensic process itself.
3. During the Preparation phase, what is the most crucial policy element to have in place?
A. A standard email retention policy.
B. A clearly defined Chain of Custody (CoC) form.
C. A list of employee passwords.
D. A backup of all financial data.
Correct Answer: B
,Rationale: The Preparation phase requires having tools, policies, and forms ready. A Chain of
Custody form is essential for maintaining the integrity and admissibility of evidence. Email retention
and financial backups are separate compliance issues.
4. You arrive at John Doe's desk. The computer is on, showing a Windows desktop. What is the first
volatile data you MUST capture?
A. The contents of the Recycle Bin.
B. The contents of RAM (Random Access Memory).
C. The Master Boot Record (MBR).
D. The Windows Event Logs.
Correct Answer: B
Rationale: Volatile data degrades over time. RAM contains running processes, network connections,
and encryption keys. It is lost when the power is removed. Event logs and MBR are non-volatile and
stored on the hard drive.
5. You execute a memory capture tool (e.g., DumpIt) on WS-045. After capturing RAM, what should
you do immediately?
A. Run a full antivirus scan.
B. Perform a graceful shutdown via the Start Menu.
C. Remove the hard drive and connect it to a write-blocker.
D. Document the SHA-256 hash of the memory dump file.
Correct Answer: D
Rationale: Hashing the captured file (memory dump) immediately creates a digital fingerprint to
verify integrity later. After capturing volatile memory, you should perform a hard power-off (pull the
plug) to preserve the state of the hard drive, not a graceful shutdown.
6. You legally acquire the hard drive from WS-045. Before imaging, you must attach it to a write-
blocker. What is the primary purpose of a hardware write-blocker?
A. To speed up the imaging process via USB 3.0.
B. To prevent any data from being written to the source drive.
C. To decrypt BitLocker-encrypted drives automatically.
D. To sanitize the drive of malware before analysis.
Correct Answer: B
,Rationale: The cardinal rule of forensics is to never modify the original evidence. A write-blocker
ensures that the operating system cannot write metadata (like last access timestamps) to the
suspect drive.
7. You use FTK Imager to create a forensic image. Which imaging method is the most forensically
sound?
A. Logical acquisition of the C: drive only.
B. Sparse acquisition of only ".docx" files.
C. Bit-for-bit (sector-by-sector) acquisition.
D. Network acquisition over the company LAN.
Correct Answer: C
Rationale: A bit-for-bit image captures the entire storage medium, including slack space, unallocated
clusters, and deleted files. Logical and sparse acquisitions miss critical hidden data.
8. During imaging, FTK Imager generates a hash. Which hash algorithm is currently the industry
standard for forensic verification?
A. MD5
B. SHA-1
C. SHA-256
D. CRC32
Correct Answer: C
Rationale: While MD5 and SHA-1 are still used, SHA-256 is considered more cryptographically secure
and is the current NIST-recommended standard for forensic integrity. CRC32 is for error detection,
not forensic validation.
9. You analyze the image in Autopsy/Sleuth Kit. You find a file with a "Zone.Identifier" alternate data
stream (ADS). What does this indicate?
A. The file was created locally by John Doe.
B. The file was downloaded from the internet (e.g., a browser).
C. The file is a system file protected by Windows.
D. The file is encrypted with EFS.
Correct Answer: B
, Rationale: A "Zone.Identifier" ADS is added by Windows when a file is downloaded from the
internet. It contains a "ZoneId" (e.g., ZoneId=3 for Internet). This is crucial for tracing the origin of
malware or exfiltrated data.
10. In the Windows Registry, what hive is most critical for identifying programs set to run at system
startup?
A. SAM
B. SECURITY
C. SYSTEM
D. NTUSER.DAT
Correct Answer: D
Rationale: NTUSER.DAT contains the HKEY_CURRENT_USER hive for a specific user (John Doe). The
"Run" and "RunOnce" keys reside here and in
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
11. You review the Windows Security Event Log (Event ID 4624). What does this event specifically
track?
A. Failed logon attempts.
B. Successful logon attempts.
C. Process creation.
D. File deletion.
Correct Answer: B
Rationale: Event ID 4624 is "An account was successfully logged on." Event ID 4625 tracks failed
logons. This helps identify if John Doe was logged in at the time of exfiltration.
12. Your analysis reveals that malware connected to an external IP address 185.xxx.xx.5. What is this
data point called?
A. A file hash (IOC)
B. A network indicator (IOC)
C. A behavioral signature
D. A threat vector
Correct Answer: B
Rationale: An Indicator of Compromise (IOC) is evidence of a breach. IP addresses, domain names,
and URLs are classified as network-based IOCs.