Governors University C702 Master's Course Study Guide, Exam
Prep, Computer Forensics, Network Intrusion, Digital Evidence,
Disk & File System Forensics, Operating System Forensics,
Device Forensics, Audits, Investigations, Cybersecurity Practice
Questions & Answers
Question 1: A hospital’s security team discovers that a former employee
accessed patient records after termination. Law enforcement is notified and a
prosecutor files charges. Which category of investigation does this represent?
A. Administrative
B. Civil
C. Criminal
D. Regulatory
CORRECT ANSWER: C. Criminal
Rationale: A criminal investigation is initiated by law enforcement in response to a
suspected violation of criminal law, such as unauthorized access to protected
health information. Administrative investigations involve internal policy
violations, civil investigations involve disputes between private parties seeking
damages, and regulatory investigations involve government agency compliance
enforcement.
Question 2: Which principle states that a forensic examiner must not continue
an investigation if it exceeds their knowledge or skill level?
A. Locard’s Exchange Principle
B. Chain of Custody
C. Competency Boundary
D. Best Evidence Rule
CORRECT ANSWER: C. Competency Boundary
Rationale: The competency boundary principle requires forensic examiners to
acknowledge their limitations and not proceed with examinations beyond their
expertise. This ensures the integrity of the investigation and prevents inaccurate
or inadmissible findings.
,Question 3: What is the primary purpose of maintaining a chain of custody
document?
A. To record the cost of evidence storage
B. To document the chronological history of evidence possession and control
C. To identify the suspect in a criminal case
D. To summarize the investigator’s conclusions
CORRECT ANSWER: B. To document the chronological history of evidence
possession and control
Rationale: A chain of custody provides an unbroken record of who handled
evidence, when, and for what purpose. This documentation establishes that
evidence has not been tampered with or compromised, making it admissible in
court.
Question 4: An investigator arrives at a crime scene where a computer is
powered on and running. What is the FIRST action the investigator should take?
A. Immediately power off the computer
B. Photograph the screen and capture volatile data
C. Disconnect the computer from the network
D. Remove the hard drive for imaging
CORRECT ANSWER: B. Photograph the screen and capture volatile data
Rationale: When a computer is powered on, volatile data such as RAM contents,
running processes, and network connections exist only while power is
maintained. The first responder should document the current state and capture
volatile data before any action that might alter or destroy it.
Question 5: Which type of cybercrime investigation involves a dispute between
two private parties seeking monetary damages?
A. Administrative
B. Criminal
C. Civil
D. Internal
CORRECT ANSWER: C. Civil
,Rationale: Civil investigations arise from disputes between private parties, such as
breach of contract or intellectual property disputes, where the remedy sought is
typically monetary damages rather than criminal prosecution.
Question 6: What is the correct order of volatility for digital evidence, from
most volatile to least volatile?
A. Hard drive, RAM, network connections, cache
B. RAM, cache, network connections, hard drive
C. Network connections, RAM, cache, hard drive
D. Cache, network connections, RAM, hard drive
CORRECT ANSWER: B. RAM, cache, network connections, hard drive
Rationale: The order of volatility dictates that the most volatile data should be
collected first. RAM and processor cache lose their contents when power is
removed. Network connections and running processes are next, followed by non-
volatile storage such as hard drives.
Question 7: Which term describes temporary information on a device that
requires constant power to persist?
A. Non-volatile data
B. Persistent data
C. Volatile data
D. Archived data
CORRECT ANSWER: C. Volatile data
Rationale: Volatile data exists only while the system has power. Examples include
RAM contents, running processes, and open network connections. Once power is
lost, this data is irretrievable, making its capture a priority in forensic
investigations.
Question 8: What is the primary function of a write blocker in digital forensics?
A. To encrypt evidence during transport
B. To prevent any modification of the source drive during imaging
C. To increase data transfer speed
D. To compress forensic images
, CORRECT ANSWER: B. To prevent any modification of the source drive during
imaging
Rationale: A write blocker is a hardware or software tool that allows read-only
access to a storage device, ensuring that the forensic imaging process does not
alter the original evidence in any way.
Question 9: Which hashing algorithm is commonly used to verify the integrity of
forensic images?
A. AES-256
B. MD5
C. RSA
D. DES
CORRECT ANSWER: B. MD5
Rationale: MD5 (Message Digest Algorithm 5) produces a 128-bit hash value
commonly used in digital forensics to verify that a forensic image is an exact
duplicate of the original evidence. Any change to the data would produce a
different hash value.
Question 10: What is the goal of forensic science in the context of digital
investigations?
A. To recover deleted files for personal use
B. To determine the evidential value of the crime scene and related evidence
C. To install security software on compromised systems
D. To monitor network traffic in real time
CORRECT ANSWER: B. To determine the evidential value of the crime scene and
related evidence
Rationale: The goal of forensic science is to identify, preserve, analyze, and
present evidence in a manner that establishes its relevance and reliability for legal
proceedings. This applies equally to digital evidence.
Question 11: Which type of investigation is conducted internally by an
organization to determine if employees are following company policies?