WGU Master's Course C702 - Forensics
and Network Intrusion With Complete
Solution
Section 1: Digital Forensics Fundamentals & Legal Frameworks (Q1–Q25)
1. Which definition BEST describes the practice of computer forensics?
A. Installing and configuring firewalls, antivirus software, and intrusion prevention
systems to stop intrusions before evidence is created
B. Methodological procedures for identifying, gathering, preserving, extracting,
interpreting, documenting, and presenting digital evidence in a legally admissible
manner
C. Penetration testing of networks and applications to discover exploitable
weaknesses before attackers find them
D. Statistical analysis of log files to forecast which workstations are most likely to
be compromised next quarter
Correct Answer: B
Rationale: Computer forensics is formally defined as methodological
(systematic) procedures for identifying, gathering, preserving, extracting,
interpreting, documenting, and presenting digital evidence so that it remains
legally admissible. Option A describes preventive hardening, Option C describes
penetration testing, and Option D describes predictive analytics—all useful
security disciplines but none constitute forensic practice. The emphasis on
methodology and admissibility is what separates forensics from routine IT work,
because every step must survive legal scrutiny in court.
2. A company sues a former vendor alleging breach of contract after email
records show the vendor misused proprietary customer data. Both parties are
,private businesses seeking monetary damages. Which type of investigation
applies?
A. Administrative, because the dispute is internal to the same industry
B. Criminal, because data misuse is always prosecuted by the state
C. Civil, because it is a dispute between parties seeking remediation or damages
D. Regulatory, because federal agencies must lead all electronic discovery
Correct Answer: C
Rationale: A lawsuit between two private parties seeking damages is a civil
dispute, so the supporting investigation is a civil investigation with electronic
discovery obligations. A criminal investigation requires a suspected violation of
criminal law and a law enforcement response, which is absent here. An
administrative investigation covers internal policy violations within an
organization, not inter-company contract disputes. The remedy sought—monetary
damages rather than prosecution—further confirms the civil category.
3. An employee is accused of repeatedly browsing prohibited websites in
violation of the organization's acceptable use policy. Security staff document the
browsing history, Human Resources schedules a disciplinary hearing, and no law
enforcement agency is involved. This proceeding is BEST classified as:
A. An administrative investigation of an internal policy violation
B. A criminal investigation handled by prosecutors
C. A civil lawsuit between the employee and the company
D. A regulatory audit mandated by federal statute
Correct Answer: A
Rationale: Investigating an internal violation of an acceptable use policy by
the organization's own staff, with HR handling discipline and no police
involvement, is the classic administrative investigation. Criminal investigations
respond to suspected violations of law and are led by law enforcement. Civil
investigations resolve disputes between separate parties seeking remedies, and
,there is no second disputing party here. Regulatory audits are conducted under
government mandate, which does not apply to routine workplace policy
enforcement.
4. Attackers deploy ransomware across a hospital network. The incident is
reported to the police, who begin building a prosecution case and obtain
warrants to seize servers controlled by the suspects. Which investigation
category is described?
A. Civil litigation between the hospital and its insurer
B. Administrative review of hospital acceptable use policy
C. Internal audit of backup and recovery controls
D. Criminal investigation, because law enforcement is responding to a suspected
violation of criminal law
Correct Answer: D
Rationale: When law enforcement responds to suspected law violations—
here the deployment of ransomware—and builds a prosecution case supported by
judicial warrants, the matter is a criminal investigation. Civil litigation seeks
damages between parties and is not described in this scenario. Administrative
review would be an internal policy matter, and an internal audit is a routine
organizational control rather than a prosecution. The presence of police,
prosecutors, and warrants is the defining marker of the criminal category.
5. During an internal administrative review, an investigator discovers evidence
that a payroll manager has been falsifying records to steal funds—conduct that
violates criminal law. What should the investigator do NEXT?
A. Treat the administrative finding as final and close the matter internally
B. Refer the matter to law enforcement, which may convert it into a criminal
investigation
, C. Destroy the collected evidence to protect the employee's privacy
D. File a civil lawsuit in place of any other action
Correct Answer: B
Rationale: When an administrative investigation uncovers evidence of criminal
conduct, the appropriate next step is to refer the matter to law enforcement. The
discovery of criminal activity transforms what began as an internal policy matter
into a potential criminal case that must be handled by proper authorities.
Continuing to handle a criminal matter internally would be inappropriate, and
destroying evidence would constitute obstruction.
6. Which model or legislation applies a holistic approach toward any criminal
activity as a criminal operation?
A. Enterprise Theory of Investigation
B. Racketeer Influenced and Corrupt Organizations Act
C. Evidence Examination
D. Law Enforcement Cyber Incident Reporting
Correct Answer: A
Rationale: The Enterprise Theory of Investigation (ETI) adopts a holistic
approach toward criminal activity, treating it as a criminal operation rather than as
a single isolated criminal act. This methodology recognizes that modern criminal
enterprises, including cybercrime groups, operate as interconnected networks and
must be investigated as such. The RICO Act is a specific statute, not a holistic
investigative model.
7. What does a forensic investigator need to obtain before seizing a computing
device in a criminal case?
A. Court warrant
B. Completed crime report
and Network Intrusion With Complete
Solution
Section 1: Digital Forensics Fundamentals & Legal Frameworks (Q1–Q25)
1. Which definition BEST describes the practice of computer forensics?
A. Installing and configuring firewalls, antivirus software, and intrusion prevention
systems to stop intrusions before evidence is created
B. Methodological procedures for identifying, gathering, preserving, extracting,
interpreting, documenting, and presenting digital evidence in a legally admissible
manner
C. Penetration testing of networks and applications to discover exploitable
weaknesses before attackers find them
D. Statistical analysis of log files to forecast which workstations are most likely to
be compromised next quarter
Correct Answer: B
Rationale: Computer forensics is formally defined as methodological
(systematic) procedures for identifying, gathering, preserving, extracting,
interpreting, documenting, and presenting digital evidence so that it remains
legally admissible. Option A describes preventive hardening, Option C describes
penetration testing, and Option D describes predictive analytics—all useful
security disciplines but none constitute forensic practice. The emphasis on
methodology and admissibility is what separates forensics from routine IT work,
because every step must survive legal scrutiny in court.
2. A company sues a former vendor alleging breach of contract after email
records show the vendor misused proprietary customer data. Both parties are
,private businesses seeking monetary damages. Which type of investigation
applies?
A. Administrative, because the dispute is internal to the same industry
B. Criminal, because data misuse is always prosecuted by the state
C. Civil, because it is a dispute between parties seeking remediation or damages
D. Regulatory, because federal agencies must lead all electronic discovery
Correct Answer: C
Rationale: A lawsuit between two private parties seeking damages is a civil
dispute, so the supporting investigation is a civil investigation with electronic
discovery obligations. A criminal investigation requires a suspected violation of
criminal law and a law enforcement response, which is absent here. An
administrative investigation covers internal policy violations within an
organization, not inter-company contract disputes. The remedy sought—monetary
damages rather than prosecution—further confirms the civil category.
3. An employee is accused of repeatedly browsing prohibited websites in
violation of the organization's acceptable use policy. Security staff document the
browsing history, Human Resources schedules a disciplinary hearing, and no law
enforcement agency is involved. This proceeding is BEST classified as:
A. An administrative investigation of an internal policy violation
B. A criminal investigation handled by prosecutors
C. A civil lawsuit between the employee and the company
D. A regulatory audit mandated by federal statute
Correct Answer: A
Rationale: Investigating an internal violation of an acceptable use policy by
the organization's own staff, with HR handling discipline and no police
involvement, is the classic administrative investigation. Criminal investigations
respond to suspected violations of law and are led by law enforcement. Civil
investigations resolve disputes between separate parties seeking remedies, and
,there is no second disputing party here. Regulatory audits are conducted under
government mandate, which does not apply to routine workplace policy
enforcement.
4. Attackers deploy ransomware across a hospital network. The incident is
reported to the police, who begin building a prosecution case and obtain
warrants to seize servers controlled by the suspects. Which investigation
category is described?
A. Civil litigation between the hospital and its insurer
B. Administrative review of hospital acceptable use policy
C. Internal audit of backup and recovery controls
D. Criminal investigation, because law enforcement is responding to a suspected
violation of criminal law
Correct Answer: D
Rationale: When law enforcement responds to suspected law violations—
here the deployment of ransomware—and builds a prosecution case supported by
judicial warrants, the matter is a criminal investigation. Civil litigation seeks
damages between parties and is not described in this scenario. Administrative
review would be an internal policy matter, and an internal audit is a routine
organizational control rather than a prosecution. The presence of police,
prosecutors, and warrants is the defining marker of the criminal category.
5. During an internal administrative review, an investigator discovers evidence
that a payroll manager has been falsifying records to steal funds—conduct that
violates criminal law. What should the investigator do NEXT?
A. Treat the administrative finding as final and close the matter internally
B. Refer the matter to law enforcement, which may convert it into a criminal
investigation
, C. Destroy the collected evidence to protect the employee's privacy
D. File a civil lawsuit in place of any other action
Correct Answer: B
Rationale: When an administrative investigation uncovers evidence of criminal
conduct, the appropriate next step is to refer the matter to law enforcement. The
discovery of criminal activity transforms what began as an internal policy matter
into a potential criminal case that must be handled by proper authorities.
Continuing to handle a criminal matter internally would be inappropriate, and
destroying evidence would constitute obstruction.
6. Which model or legislation applies a holistic approach toward any criminal
activity as a criminal operation?
A. Enterprise Theory of Investigation
B. Racketeer Influenced and Corrupt Organizations Act
C. Evidence Examination
D. Law Enforcement Cyber Incident Reporting
Correct Answer: A
Rationale: The Enterprise Theory of Investigation (ETI) adopts a holistic
approach toward criminal activity, treating it as a criminal operation rather than as
a single isolated criminal act. This methodology recognizes that modern criminal
enterprises, including cybercrime groups, operate as interconnected networks and
must be investigated as such. The RICO Act is a specific statute, not a holistic
investigative model.
7. What does a forensic investigator need to obtain before seizing a computing
device in a criminal case?
A. Court warrant
B. Completed crime report