Intrusion Objective Assessment Study Guide, WGU C702 Exam Prep,
Digital Forensics, Network Security, Intrusion Detection,
Cybersecurity, Incident Response, Evidence Collection, Malware
Analysis, Practice Questions, Answers & Rationales
Question 1: Which definition BEST describes the practice of computer forensics
for a corporate analyst role description?
A. Installing and configuring firewalls, antivirus software, and intrusion prevention
systems to stop intrusions before evidence is created
B. Methodological procedures for identifying, gathering, preserving, extracting,
interpreting, documenting, and presenting digital evidence in a legally admissible
manner
C. Penetration testing of networks and applications to discover exploitable
weaknesses before attackers find them
D. Statistical analysis of log files to forecast which workstations are most likely to
be compromised next quarter
CORRECT ANSWER: B. Methodological procedures for identifying, gathering,
preserving, extracting, interpreting, documenting, and presenting digital
evidence in a legally admissible manner
Rationale: Computer forensics is formally defined as methodological procedures
for identifying, gathering, preserving, extracting, interpreting, documenting, and
presenting digital evidence so that it remains legally admissible. Option A
describes preventive hardening, Option C describes penetration testing, and
Option D describes predictive analytics — all useful security disciplines but none
constitute forensic practice.
Question 2: A company sues a former vendor alleging breach of contract after
email records show the vendor misused proprietary customer data. Both parties
are private businesses seeking monetary damages. Which type of investigation
applies?
A. Administrative, because the dispute is internal to the same industry
B. Criminal, because data misuse is always prosecuted by the state
C. Civil, because it is a dispute between parties seeking remediation or damages
D. Regulatory, because federal agencies must lead all electronic discovery
,CORRECT ANSWER: C. Civil, because it is a dispute between parties seeking
remediation or damages
Rationale: A lawsuit between two private parties seeking damages is a civil
dispute, so the supporting investigation is a civil investigation with electronic
discovery obligations. A criminal investigation requires a suspected violation of
criminal law and a law enforcement response, which is absent here.
Question 3: An employee is accused of repeatedly browsing prohibited websites
in violation of the organization's acceptable use policy. Security staff document
the browsing history, Human Resources schedules a disciplinary hearing, and no
law enforcement agency is involved. This proceeding is BEST classified as:
A. An administrative investigation of an internal policy violation
B. A criminal investigation handled by prosecutors
C. A civil lawsuit between the employee and the company
D. A regulatory audit mandated by federal statute
CORRECT ANSWER: A. An administrative investigation of an internal policy
violation
Rationale: Investigating an internal violation of an acceptable use policy by the
organization's own staff, with HR handling discipline and no police involvement, is
the classic administrative investigation. Criminal investigations respond to
suspected violations of law and are led by law enforcement.
Question 4: Attackers deploy ransomware across a hospital network. The
incident is reported to the police, who begin building a prosecution case and
obtain warrants to seize servers controlled by the suspects. Which investigation
category is described?
A. Civil litigation between the hospital and its insurer
B. Administrative review of hospital acceptable use policy
C. Internal audit of backup and recovery controls
D. Criminal investigation, because law enforcement is responding to a suspected
violation of criminal law
CORRECT ANSWER: D. Criminal investigation, because law enforcement is
responding to a suspected violation of criminal law
,Rationale: When law enforcement responds to suspected law violations — here
the deployment of ransomware — and builds a prosecution case supported by
judicial warrants, the matter is a criminal investigation. The presence of police,
prosecutors, and warrants is the defining marker of the criminal category.
Question 5: During an internal administrative review, an investigator discovers
evidence that a payroll manager has been falsifying records to steal funds —
conduct that violates criminal law. What should the investigator do NEXT?
A. Treat the administrative finding as final and close the matter internally
B. Refer the matter to law enforcement, which may convert it into a criminal
investigation
C. Destroy the collected evidence to protect the employee's privacy
D. File a civil lawsuit in place of any other action
CORRECT ANSWER: B. Refer the matter to law enforcement, which may convert
it into a criminal investigation
Rationale: When an administrative investigation uncovers evidence of criminal
conduct, the appropriate next step is to refer the matter to law enforcement. The
discovery of criminal activity transforms what began as an internal policy matter
into a potential criminal case that must be handled by proper authorities.
Question 6: What does a forensic investigator need to obtain before seizing a
computing device in a criminal case?
A. Court warrant
B. Completed crime report
C. Chain of custody document
D. Plaintiff's permission
CORRECT ANSWER: A. Court warrant
Rationale: In criminal cases, a court warrant is required before seizing a
computing device to ensure the seizure complies with Fourth Amendment
protections against unreasonable search and seizure. A chain of custody
document is created during evidence handling, not before seizure.
, Question 7: A cybercrime investigator identifies a USB memory stick containing
emails as a primary piece of evidence. Who must sign the chain of custody
document once the USB stick is in evidence?
A. Those who obtain access to the device
B. Anyone who has ever used the device
C. Recipients of emails on the device
D. Authors of emails on the device
CORRECT ANSWER: A. Those who obtain access to the device
Rationale: The chain of custody document must be signed by every person who
obtains access to the evidence from the moment it is collected until it is
presented in court. This creates an unbroken record of who handled the evidence
and when, which is essential for legal admissibility.
Question 8: Which type of attack is a denial-of-service technique that sends a
large amount of data to overwhelm system resources?
A. Phishing
B. Spamming
C. Mail bombing
D. Bluejacking
CORRECT ANSWER: C. Mail bombing
Rationale: Mail bombing is a denial-of-service technique that floods an email
system with massive amounts of data to overwhelm system resources and render
the service unavailable. Phishing is a social engineering attack, spamming is
unsolicited bulk messaging, and bluejacking involves sending unsolicited
messages via Bluetooth.
Question 9: Which computer crime forensics step requires an investigator to
duplicate and image the collected digital information?
A. Securing evidence
B. Acquiring data
C. Analyzing data
D. Reporting findings