WGU D829 Digital Forensics: Complete
Incident Report Practice Exam WITH
VERIFIED ANSWERS AND RATIONALE
GRADED a+
1. What is the primary purpose of a digital forensic investigation?
A. To immediately restore all affected systems
B. To collect, preserve, analyze, and report digital evidence
C. To install new security tools
D. To discipline employees
Answer: B
Rationale: Digital forensics focuses on identifying, preserving, collecting, analyzing, and reporting
digital evidence in a manner that supports investigative and legal requirements.
2. Which principle is most important when handling digital evidence?
A. Evidence should be modified to make it easier to review
B. Evidence should be collected without documentation
C. Evidence integrity must be maintained
D. Evidence should be shared with all employees
Answer: C
Rationale: Maintaining integrity ensures the evidence remains authentic, reliable, and admissible.
3. What is the purpose of a chain of custody?
A. To determine the severity of an incident
B. To document possession, handling, and transfer of evidence
C. To identify malware signatures
D. To delete unnecessary evidence
,Answer: B
Rationale: A chain of custody records who collected, accessed, transferred, stored, or analyzed
evidence from collection through presentation.
4. Which item should be documented in a chain-of-custody record?
A. The investigator’s favorite forensic tool
B. The evidence description and unique identifier
C. Employee vacation schedules
D. The organization’s marketing plan
Answer: B
Rationale: Evidence descriptions, identifiers, dates, times, locations, and personnel involved are
essential chain-of-custody details.
5. Why are cryptographic hashes used in digital forensics?
A. To encrypt evidence so no one can access it
B. To verify that evidence has not changed
C. To speed up network traffic
D. To remove malware from a device
Answer: B
Rationale: Hash values provide a digital fingerprint of data. Matching hashes before and after
acquisition help prove evidence integrity.
6. Which hashing algorithm is generally considered stronger than MD5?
A. SHA-256
B. ROT13
C. Base64
D. DES
Answer: A
,Rationale: SHA-256 is a modern cryptographic hashing algorithm and is preferred over weak or
collision-prone algorithms such as MD5.
7. A forensic investigator calculates a hash before and after imaging a drive. The values match. What
does this indicate?
A. The drive contains malware
B. The image is likely an accurate copy of the original
C. The drive has been encrypted
D. The system is safe to return to production
Answer: B
Rationale: Matching hash values support the conclusion that the forensic image has not been altered
and accurately represents the source data.
8. What is the best definition of a forensic image?
A. A screenshot of a user’s desktop
B. A sector-by-sector copy of storage media
C. A photograph of a computer
D. A compressed backup file only containing documents
Answer: B
Rationale: A forensic image is typically a bit-for-bit or sector-by-sector copy that may include deleted
files, slack space, and unallocated space.
9. Which tool helps prevent writing to a storage device during acquisition?
A. Packet sniffer
B. Write blocker
C. Password manager
D. Firewall
Answer: B
Rationale: A write blocker prevents changes from being made to the original evidence device during
examination or imaging.
, 10. Why should an investigator avoid analyzing original evidence directly?
A. Original evidence is always encrypted
B. Analysis could accidentally modify the evidence
C. It is illegal to view original evidence
D. Original evidence cannot be hashed
Answer: B
Rationale: Working from a verified forensic copy protects the original evidence from accidental
alteration.
11. What is volatile data?
A. Data that remains unchanged after power loss
B. Data stored only in cloud services
C. Data that may be lost when a system is powered off
D. Data stored in a paper report
Answer: C
Rationale: Volatile data includes RAM contents, active network connections, running processes, and
logged-in users, which may disappear after shutdown.
12. Which evidence should generally be collected first from a running system?
A. Archived log files
B. Volatile memory and active system information
C. Printed policies
D. Long-term backups
Answer: B
Rationale: Volatile information may be lost if the device is shut down or restarted, so it is collected
before nonvolatile evidence.
13. Which is an example of volatile data?
Incident Report Practice Exam WITH
VERIFIED ANSWERS AND RATIONALE
GRADED a+
1. What is the primary purpose of a digital forensic investigation?
A. To immediately restore all affected systems
B. To collect, preserve, analyze, and report digital evidence
C. To install new security tools
D. To discipline employees
Answer: B
Rationale: Digital forensics focuses on identifying, preserving, collecting, analyzing, and reporting
digital evidence in a manner that supports investigative and legal requirements.
2. Which principle is most important when handling digital evidence?
A. Evidence should be modified to make it easier to review
B. Evidence should be collected without documentation
C. Evidence integrity must be maintained
D. Evidence should be shared with all employees
Answer: C
Rationale: Maintaining integrity ensures the evidence remains authentic, reliable, and admissible.
3. What is the purpose of a chain of custody?
A. To determine the severity of an incident
B. To document possession, handling, and transfer of evidence
C. To identify malware signatures
D. To delete unnecessary evidence
,Answer: B
Rationale: A chain of custody records who collected, accessed, transferred, stored, or analyzed
evidence from collection through presentation.
4. Which item should be documented in a chain-of-custody record?
A. The investigator’s favorite forensic tool
B. The evidence description and unique identifier
C. Employee vacation schedules
D. The organization’s marketing plan
Answer: B
Rationale: Evidence descriptions, identifiers, dates, times, locations, and personnel involved are
essential chain-of-custody details.
5. Why are cryptographic hashes used in digital forensics?
A. To encrypt evidence so no one can access it
B. To verify that evidence has not changed
C. To speed up network traffic
D. To remove malware from a device
Answer: B
Rationale: Hash values provide a digital fingerprint of data. Matching hashes before and after
acquisition help prove evidence integrity.
6. Which hashing algorithm is generally considered stronger than MD5?
A. SHA-256
B. ROT13
C. Base64
D. DES
Answer: A
,Rationale: SHA-256 is a modern cryptographic hashing algorithm and is preferred over weak or
collision-prone algorithms such as MD5.
7. A forensic investigator calculates a hash before and after imaging a drive. The values match. What
does this indicate?
A. The drive contains malware
B. The image is likely an accurate copy of the original
C. The drive has been encrypted
D. The system is safe to return to production
Answer: B
Rationale: Matching hash values support the conclusion that the forensic image has not been altered
and accurately represents the source data.
8. What is the best definition of a forensic image?
A. A screenshot of a user’s desktop
B. A sector-by-sector copy of storage media
C. A photograph of a computer
D. A compressed backup file only containing documents
Answer: B
Rationale: A forensic image is typically a bit-for-bit or sector-by-sector copy that may include deleted
files, slack space, and unallocated space.
9. Which tool helps prevent writing to a storage device during acquisition?
A. Packet sniffer
B. Write blocker
C. Password manager
D. Firewall
Answer: B
Rationale: A write blocker prevents changes from being made to the original evidence device during
examination or imaging.
, 10. Why should an investigator avoid analyzing original evidence directly?
A. Original evidence is always encrypted
B. Analysis could accidentally modify the evidence
C. It is illegal to view original evidence
D. Original evidence cannot be hashed
Answer: B
Rationale: Working from a verified forensic copy protects the original evidence from accidental
alteration.
11. What is volatile data?
A. Data that remains unchanged after power loss
B. Data stored only in cloud services
C. Data that may be lost when a system is powered off
D. Data stored in a paper report
Answer: C
Rationale: Volatile data includes RAM contents, active network connections, running processes, and
logged-in users, which may disappear after shutdown.
12. Which evidence should generally be collected first from a running system?
A. Archived log files
B. Volatile memory and active system information
C. Printed policies
D. Long-term backups
Answer: B
Rationale: Volatile information may be lost if the device is shut down or restarted, so it is collected
before nonvolatile evidence.
13. Which is an example of volatile data?