• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 32 pages
Exam (elaborations)

WGU D829 Digital Forensics exam with correct answers and rationale updated 2026 graded A+

Document preview thumbnail
Preview 4 out of 32 pages

WGU D829 Digital Forensics exam with correct answers and rationale updated 2026 graded A+

Content preview

WGU D829 Digital Forensics exam with
correct answers and rationale
updated 2026 graded A+

1. What is the very first action you should take upon receiving the initial alert from John Doe?

A. Immediately unplug the power cord from WS-045.

B. Create a forensic image of the hard drive using FTK Imager.

C. Interview John Doe to document the symptoms and timeline of the incident.

D. Scan the network for other compromised hosts.

Correct Answer: C

Rationale: The first step in the Identification phase is to gather initial information. Interviewing the
reporter (John Doe) establishes the scope, timeline, and symptoms. Jumping to imaging or power-off
could destroy volatile data or violate chain of custody protocols without proper context.



2. Which standard primarily dictates the principles of "defensible" forensic acquisition?

A. NIST SP 800-86

B. ISO 27001

C. ISO 27037

D. PCI DSS 4.0

Correct Answer: C

Rationale: ISO 27037 specifically provides guidelines for identification, collection, acquisition, and
preservation of digital evidence in a defensible manner. NIST SP 800-86 is a guide for integrating
forensics into incident response, but ISO 27037 focuses on the forensic process itself.



3. During the Preparation phase, what is the most crucial policy element to have in place?

A. A standard email retention policy.

B. A clearly defined Chain of Custody (CoC) form.

C. A list of employee passwords.

D. A backup of all financial data.

Correct Answer: B

,Rationale: The Preparation phase requires having tools, policies, and forms ready. A Chain of
Custody form is essential for maintaining the integrity and admissibility of evidence. Email retention
and financial backups are separate compliance issues.



4. You arrive at John Doe's desk. The computer is on, showing a Windows desktop. What is the first
volatile data you MUST capture?

A. The contents of the Recycle Bin.

B. The contents of RAM (Random Access Memory).

C. The Master Boot Record (MBR).

D. The Windows Event Logs.

Correct Answer: B

Rationale: Volatile data degrades over time. RAM contains running processes, network connections,
and encryption keys. It is lost when the power is removed. Event logs and MBR are non-volatile and
stored on the hard drive.



5. You execute a memory capture tool (e.g., DumpIt) on WS-045. After capturing RAM, what should
you do immediately?

A. Run a full antivirus scan.

B. Perform a graceful shutdown via the Start Menu.

C. Remove the hard drive and connect it to a write-blocker.

D. Document the SHA-256 hash of the memory dump file.

Correct Answer: D

Rationale: Hashing the captured file (memory dump) immediately creates a digital fingerprint to
verify integrity later. After capturing volatile memory, you should perform a hard power-off (pull the
plug) to preserve the state of the hard drive, not a graceful shutdown.



6. You legally acquire the hard drive from WS-045. Before imaging, you must attach it to a write-
blocker. What is the primary purpose of a hardware write-blocker?

A. To speed up the imaging process via USB 3.0.

B. To prevent any data from being written to the source drive.

C. To decrypt BitLocker-encrypted drives automatically.

D. To sanitize the drive of malware before analysis.

Correct Answer: B

,Rationale: The cardinal rule of forensics is to never modify the original evidence. A write-blocker
ensures that the operating system cannot write metadata (like last access timestamps) to the
suspect drive.



7. You use FTK Imager to create a forensic image. Which imaging method is the most forensically
sound?

A. Logical acquisition of the C: drive only.

B. Sparse acquisition of only ".docx" files.

C. Bit-for-bit (sector-by-sector) acquisition.

D. Network acquisition over the company LAN.

Correct Answer: C

Rationale: A bit-for-bit image captures the entire storage medium, including slack space, unallocated
clusters, and deleted files. Logical and sparse acquisitions miss critical hidden data.



8. During imaging, FTK Imager generates a hash. Which hash algorithm is currently the industry
standard for forensic verification?

A. MD5

B. SHA-1

C. SHA-256

D. CRC32

Correct Answer: C

Rationale: While MD5 and SHA-1 are still used, SHA-256 is considered more cryptographically secure
and is the current NIST-recommended standard for forensic integrity. CRC32 is for error detection,
not forensic validation.



9. You analyze the image in Autopsy/Sleuth Kit. You find a file with a "Zone.Identifier" alternate data
stream (ADS). What does this indicate?

A. The file was created locally by John Doe.

B. The file was downloaded from the internet (e.g., a browser).

C. The file is a system file protected by Windows.

D. The file is encrypted with EFS.

Correct Answer: B

, Rationale: A "Zone.Identifier" ADS is added by Windows when a file is downloaded from the
internet. It contains a "ZoneId" (e.g., ZoneId=3 for Internet). This is crucial for tracing the origin of
malware or exfiltrated data.



10. In the Windows Registry, what hive is most critical for identifying programs set to run at system
startup?

A. SAM

B. SECURITY

C. SYSTEM

D. NTUSER.DAT

Correct Answer: D

Rationale: NTUSER.DAT contains the HKEY_CURRENT_USER hive for a specific user (John Doe). The
"Run" and "RunOnce" keys reside here and in
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.



11. You review the Windows Security Event Log (Event ID 4624). What does this event specifically
track?

A. Failed logon attempts.

B. Successful logon attempts.

C. Process creation.

D. File deletion.

Correct Answer: B

Rationale: Event ID 4624 is "An account was successfully logged on." Event ID 4625 tracks failed
logons. This helps identify if John Doe was logged in at the time of exfiltration.



12. Your analysis reveals that malware connected to an external IP address 185.xxx.xx.5. What is this
data point called?

A. A file hash (IOC)

B. A network indicator (IOC)

C. A behavioral signature

D. A threat vector

Correct Answer: B

Rationale: An Indicator of Compromise (IOC) is evidence of a breach. IP addresses, domain names,
and URLs are classified as network-based IOCs.

Document information

Uploaded on
September 15, 2026
Number of pages
32
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$24.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
227
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions