• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 43 pages
Exam (elaborations)

WGU Master's Course C702 - Forensics and Network Intrusion With Complete Solution

Document preview thumbnail
Preview 4 out of 43 pages

WGU Master's Course C702 - Forensics and Network Intrusion With Complete Solution

Content preview

WGU Master's Course C702 - Forensics and
Network Intrusion With Complete Solution
Section 1: Digital Forensics Fundamentals (Questions 1–20)

1. Which of the following best defines digital forensics?

A. The process of recovering deleted files from a hard drive
B. The application of scientific methods to identify, collect, preserve, analyze, and present digital
evidence
C. The use of hacking tools to test network security
D. The monitoring of network traffic for performance issues

Correct Answer: B

Rationale: Digital forensics is a scientific discipline focused on the identification, collection,
preservation, analysis, and presentation of digital evidence in a legally defensible manner.
Option A is too narrow (only recovery). Option C describes penetration testing. Option D
describes network monitoring, not forensics.



2. Which of the following are core phases of the digital forensics process? (Select All That
Apply)

A. Identification
B. Preservation
C. Analysis
D. Marketing
E. Presentation

Correct Answers: A, B, C, E

Rationale: The standard digital forensics process includes identification, preservation,
collection, examination, analysis, and presentation. "Marketing" is not a forensic phase. These
phases follow the NIST SP 800-86 framework.



3. A forensic investigator arrives at a scene and finds a computer powered on with a
screensaver active. What should the investigator do FIRST?

,A. Immediately unplug the computer to preserve the hard drive
B. Photograph the screen and capture volatile data before shutting down
C. Shut down the computer using the Start menu
D. Remove the hard drive and create an image

Correct Answer: B

Rationale: When a system is live, volatile data (RAM, network connections, running
processes) must be captured first. Photographing the screen preserves the current state.
Unplugging (A) or shutting down (C) destroys volatile evidence. Removing the drive (D) is
premature and skips volatile data capture.



4. Which of the following is considered volatile data? (Select All That Apply)

A. RAM contents
B. Running processes
C. Data on a powered-off USB drive
D. Network connection states
E. Temporary files on disk

Correct Answers: A, B, D

Rationale: Volatile data is lost when power is removed. RAM, running processes, and
network connections are volatile. A powered-off USB drive (C) retains data (non-volatile).
Temporary files on disk (E) persist after shutdown, so they are non-volatile.



5. What is the primary purpose of a write blocker in forensic investigations?

A. To speed up the imaging process
B. To prevent any modification of the source drive during acquisition
C. To encrypt the forensic image
D. To compress the image for storage

Correct Answer: B

Rationale: A write blocker ensures that no data is written to the source drive during
imaging, preserving evidentiary integrity. It does not speed up imaging (A), encrypt (C), or
compress (D).

,6. Which hash algorithm is currently recommended for forensic integrity verification due to its
resistance to collision attacks?

A. MD5
B. SHA-1
C. SHA-256
D. CRC32

Correct Answer: C

Rationale: SHA-256 is collision-resistant and recommended for forensic use. MD5 (A) and
SHA-1 (B) have known collision vulnerabilities. CRC32 (D) is a checksum, not a cryptographic
hash.



7. The order of volatility suggests which of the following should be collected first?

A. Hard drive contents
B. CPU cache and registers
C. USB drive contents
D. Archived backups

Correct Answer: B

Rationale: According to RFC 3227, the order of volatility starts with the most volatile: CPU
registers/cache, then RAM, then network state, then disk, then backups. CPU cache/registers
are the most volatile.



8. Which of the following describes "forensic soundness"?

A. Using only open-source tools
B. Ensuring evidence is collected and handled in a manner that preserves its integrity and
admissibility
C. Encrypting all evidence
D. Completing the investigation within 24 hours

Correct Answer: B

Rationale: Forensic soundness means the evidence is collected, preserved, and analyzed in
a way that maintains its integrity and admissibility in court. Tool choice (A), encryption (C), and
speed (D) are not defining factors.

, 9. A forensic image differs from a forensic copy in that:

A. An image is a bit-for-bit duplicate, while a copy may only include allocated files
B. A copy is always encrypted
C. An image is smaller than a copy
D. A copy includes deleted files, but an image does not

Correct Answer: A

Rationale: A forensic image is a bit-for-bit duplicate of the entire drive, including slack space
and unallocated space. A forensic copy may only include logical files. Images typically include
deleted data; copies may not.



10. Which of the following are valid forensic imaging formats? (Select All That Apply)

A. RAW (dd)
B. E01
C. AFF
D. DOCX
E. ISO

Correct Answers: A, B, C

Rationale: RAW, E01 (EnCase), and AFF (Advanced Forensic Format) are valid forensic image
formats. DOCX (D) is a word processing format. ISO (E) is an optical disc image, not typically
used for forensic disk imaging of hard drives, though it can be used for optical media.



11. What is slack space?

A. Space between partitions
B. Unused space within the last cluster allocated to a file
C. Deleted file space
D. RAM swap space

Correct Answer: B

Rationale: Slack space is the unused portion of the last cluster allocated to a file. It can
contain remnants of previous data. It is not the same as unallocated space (C) or partition gaps
(A).

Document information

Uploaded on
September 27, 2026
Number of pages
43
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.59

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
353
Last sold
-




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions