WGU Master's Course C702 - Forensics and
Network Intrusion With Complete Solution
Section 1: Digital Forensics Fundamentals (Questions 1–20)
1. Which of the following best defines digital forensics?
A. The process of recovering deleted files from a hard drive
B. The application of scientific methods to identify, collect, preserve, analyze, and present digital
evidence
C. The use of hacking tools to test network security
D. The monitoring of network traffic for performance issues
Correct Answer: B
Rationale: Digital forensics is a scientific discipline focused on the identification, collection,
preservation, analysis, and presentation of digital evidence in a legally defensible manner.
Option A is too narrow (only recovery). Option C describes penetration testing. Option D
describes network monitoring, not forensics.
2. Which of the following are core phases of the digital forensics process? (Select All That
Apply)
A. Identification
B. Preservation
C. Analysis
D. Marketing
E. Presentation
Correct Answers: A, B, C, E
Rationale: The standard digital forensics process includes identification, preservation,
collection, examination, analysis, and presentation. "Marketing" is not a forensic phase. These
phases follow the NIST SP 800-86 framework.
3. A forensic investigator arrives at a scene and finds a computer powered on with a
screensaver active. What should the investigator do FIRST?
,A. Immediately unplug the computer to preserve the hard drive
B. Photograph the screen and capture volatile data before shutting down
C. Shut down the computer using the Start menu
D. Remove the hard drive and create an image
Correct Answer: B
Rationale: When a system is live, volatile data (RAM, network connections, running
processes) must be captured first. Photographing the screen preserves the current state.
Unplugging (A) or shutting down (C) destroys volatile evidence. Removing the drive (D) is
premature and skips volatile data capture.
4. Which of the following is considered volatile data? (Select All That Apply)
A. RAM contents
B. Running processes
C. Data on a powered-off USB drive
D. Network connection states
E. Temporary files on disk
Correct Answers: A, B, D
Rationale: Volatile data is lost when power is removed. RAM, running processes, and
network connections are volatile. A powered-off USB drive (C) retains data (non-volatile).
Temporary files on disk (E) persist after shutdown, so they are non-volatile.
5. What is the primary purpose of a write blocker in forensic investigations?
A. To speed up the imaging process
B. To prevent any modification of the source drive during acquisition
C. To encrypt the forensic image
D. To compress the image for storage
Correct Answer: B
Rationale: A write blocker ensures that no data is written to the source drive during
imaging, preserving evidentiary integrity. It does not speed up imaging (A), encrypt (C), or
compress (D).
,6. Which hash algorithm is currently recommended for forensic integrity verification due to its
resistance to collision attacks?
A. MD5
B. SHA-1
C. SHA-256
D. CRC32
Correct Answer: C
Rationale: SHA-256 is collision-resistant and recommended for forensic use. MD5 (A) and
SHA-1 (B) have known collision vulnerabilities. CRC32 (D) is a checksum, not a cryptographic
hash.
7. The order of volatility suggests which of the following should be collected first?
A. Hard drive contents
B. CPU cache and registers
C. USB drive contents
D. Archived backups
Correct Answer: B
Rationale: According to RFC 3227, the order of volatility starts with the most volatile: CPU
registers/cache, then RAM, then network state, then disk, then backups. CPU cache/registers
are the most volatile.
8. Which of the following describes "forensic soundness"?
A. Using only open-source tools
B. Ensuring evidence is collected and handled in a manner that preserves its integrity and
admissibility
C. Encrypting all evidence
D. Completing the investigation within 24 hours
Correct Answer: B
Rationale: Forensic soundness means the evidence is collected, preserved, and analyzed in
a way that maintains its integrity and admissibility in court. Tool choice (A), encryption (C), and
speed (D) are not defining factors.
, 9. A forensic image differs from a forensic copy in that:
A. An image is a bit-for-bit duplicate, while a copy may only include allocated files
B. A copy is always encrypted
C. An image is smaller than a copy
D. A copy includes deleted files, but an image does not
Correct Answer: A
Rationale: A forensic image is a bit-for-bit duplicate of the entire drive, including slack space
and unallocated space. A forensic copy may only include logical files. Images typically include
deleted data; copies may not.
10. Which of the following are valid forensic imaging formats? (Select All That Apply)
A. RAW (dd)
B. E01
C. AFF
D. DOCX
E. ISO
Correct Answers: A, B, C
Rationale: RAW, E01 (EnCase), and AFF (Advanced Forensic Format) are valid forensic image
formats. DOCX (D) is a word processing format. ISO (E) is an optical disc image, not typically
used for forensic disk imaging of hard drives, though it can be used for optical media.
11. What is slack space?
A. Space between partitions
B. Unused space within the last cluster allocated to a file
C. Deleted file space
D. RAM swap space
Correct Answer: B
Rationale: Slack space is the unused portion of the last cluster allocated to a file. It can
contain remnants of previous data. It is not the same as unallocated space (C) or partition gaps
(A).
Network Intrusion With Complete Solution
Section 1: Digital Forensics Fundamentals (Questions 1–20)
1. Which of the following best defines digital forensics?
A. The process of recovering deleted files from a hard drive
B. The application of scientific methods to identify, collect, preserve, analyze, and present digital
evidence
C. The use of hacking tools to test network security
D. The monitoring of network traffic for performance issues
Correct Answer: B
Rationale: Digital forensics is a scientific discipline focused on the identification, collection,
preservation, analysis, and presentation of digital evidence in a legally defensible manner.
Option A is too narrow (only recovery). Option C describes penetration testing. Option D
describes network monitoring, not forensics.
2. Which of the following are core phases of the digital forensics process? (Select All That
Apply)
A. Identification
B. Preservation
C. Analysis
D. Marketing
E. Presentation
Correct Answers: A, B, C, E
Rationale: The standard digital forensics process includes identification, preservation,
collection, examination, analysis, and presentation. "Marketing" is not a forensic phase. These
phases follow the NIST SP 800-86 framework.
3. A forensic investigator arrives at a scene and finds a computer powered on with a
screensaver active. What should the investigator do FIRST?
,A. Immediately unplug the computer to preserve the hard drive
B. Photograph the screen and capture volatile data before shutting down
C. Shut down the computer using the Start menu
D. Remove the hard drive and create an image
Correct Answer: B
Rationale: When a system is live, volatile data (RAM, network connections, running
processes) must be captured first. Photographing the screen preserves the current state.
Unplugging (A) or shutting down (C) destroys volatile evidence. Removing the drive (D) is
premature and skips volatile data capture.
4. Which of the following is considered volatile data? (Select All That Apply)
A. RAM contents
B. Running processes
C. Data on a powered-off USB drive
D. Network connection states
E. Temporary files on disk
Correct Answers: A, B, D
Rationale: Volatile data is lost when power is removed. RAM, running processes, and
network connections are volatile. A powered-off USB drive (C) retains data (non-volatile).
Temporary files on disk (E) persist after shutdown, so they are non-volatile.
5. What is the primary purpose of a write blocker in forensic investigations?
A. To speed up the imaging process
B. To prevent any modification of the source drive during acquisition
C. To encrypt the forensic image
D. To compress the image for storage
Correct Answer: B
Rationale: A write blocker ensures that no data is written to the source drive during
imaging, preserving evidentiary integrity. It does not speed up imaging (A), encrypt (C), or
compress (D).
,6. Which hash algorithm is currently recommended for forensic integrity verification due to its
resistance to collision attacks?
A. MD5
B. SHA-1
C. SHA-256
D. CRC32
Correct Answer: C
Rationale: SHA-256 is collision-resistant and recommended for forensic use. MD5 (A) and
SHA-1 (B) have known collision vulnerabilities. CRC32 (D) is a checksum, not a cryptographic
hash.
7. The order of volatility suggests which of the following should be collected first?
A. Hard drive contents
B. CPU cache and registers
C. USB drive contents
D. Archived backups
Correct Answer: B
Rationale: According to RFC 3227, the order of volatility starts with the most volatile: CPU
registers/cache, then RAM, then network state, then disk, then backups. CPU cache/registers
are the most volatile.
8. Which of the following describes "forensic soundness"?
A. Using only open-source tools
B. Ensuring evidence is collected and handled in a manner that preserves its integrity and
admissibility
C. Encrypting all evidence
D. Completing the investigation within 24 hours
Correct Answer: B
Rationale: Forensic soundness means the evidence is collected, preserved, and analyzed in
a way that maintains its integrity and admissibility in court. Tool choice (A), encryption (C), and
speed (D) are not defining factors.
, 9. A forensic image differs from a forensic copy in that:
A. An image is a bit-for-bit duplicate, while a copy may only include allocated files
B. A copy is always encrypted
C. An image is smaller than a copy
D. A copy includes deleted files, but an image does not
Correct Answer: A
Rationale: A forensic image is a bit-for-bit duplicate of the entire drive, including slack space
and unallocated space. A forensic copy may only include logical files. Images typically include
deleted data; copies may not.
10. Which of the following are valid forensic imaging formats? (Select All That Apply)
A. RAW (dd)
B. E01
C. AFF
D. DOCX
E. ISO
Correct Answers: A, B, C
Rationale: RAW, E01 (EnCase), and AFF (Advanced Forensic Format) are valid forensic image
formats. DOCX (D) is a word processing format. ISO (E) is an optical disc image, not typically
used for forensic disk imaging of hard drives, though it can be used for optical media.
11. What is slack space?
A. Space between partitions
B. Unused space within the last cluster allocated to a file
C. Deleted file space
D. RAM swap space
Correct Answer: B
Rationale: Slack space is the unused portion of the last cluster allocated to a file. It can
contain remnants of previous data. It is not the same as unallocated space (C) or partition gaps
(A).