WGU C702 FORENSICS AND NETWORK INTRUSION FINAL
EXAM 2024-2025 COMPLETE ACTUAL EXAM REAL
QUESTIONS AND CORRECT DETAILED ANSWERS
(CORRECT VERIFIED ANSWERS) LATEST UPDATED
VERSION |ALREADY GRADED A+ (REVISED EXAM)
Program Packers - Answer-Used by attackers to hide their data.
In this regard, the technique is similar to cryptography. The
packers compress the files using various algorithms. Hence,
unless the investigators know the tool that has been used to
pack the file and have a tool to unpack it, they will not be able
to access it.
Windows Logged-On Commands - Answer-Net Sessions
PSLoggedOn
LogonSessions
Net file - Answer-A windows command used to determine open
files.
Nbstat -c - Answer-A command used to display the NetBIOS
name table cache in Windows and active TCP (or UDP)
connections, as well as a host of other statistics.
,Microsoft Security ID - Answer-Refers to a unique identification
number that Microsoft assigns to a Windows user account for
granting the user access to a particular resource.
Wevtutil - Answer-This tool enables you to retrieve information
about event logs and publishers. You can also use this
command to install and uninstall event manifests; to run
queries; and to export, archive, and clear logs.
Commands for showing Windows Processes - Answer-Pslist
Tasklist
Listdlls
Handle
Shellbags - Answer-Contains user-specific Windows OS folder
and viewing preferences to Windows Explorer. It can tell us
which folders were accessed on the local machine, network,
and/or removable devices, and when.
BagMRU - Answer-Based on the keys that are here, you can tell
which directories were opened/closed during a time period.
, CustomDestinations Jump List - Answer-These files are created
when a user pins a file or an application to the taskbar.
There are also AutomaticDestinations which are just files
created by the Windows OS.
dmesg - Answer-Displays the contents of the kernel ring buffer.
Three Tiers of Log Management - Answer-Log Generation
Log Monitoring
Log Analysis/Storage
Postmortem Analysis - Answer-A type of log analysis to
investigate an incident that has already happened. The
alternative would be Real-time analysis which is analysis of an
ongoing attack.
A case involving a noncriminal matter such as a contract
dispute or a claim of patent infringement between two parties.
Answer- Civil Case
EXAM 2024-2025 COMPLETE ACTUAL EXAM REAL
QUESTIONS AND CORRECT DETAILED ANSWERS
(CORRECT VERIFIED ANSWERS) LATEST UPDATED
VERSION |ALREADY GRADED A+ (REVISED EXAM)
Program Packers - Answer-Used by attackers to hide their data.
In this regard, the technique is similar to cryptography. The
packers compress the files using various algorithms. Hence,
unless the investigators know the tool that has been used to
pack the file and have a tool to unpack it, they will not be able
to access it.
Windows Logged-On Commands - Answer-Net Sessions
PSLoggedOn
LogonSessions
Net file - Answer-A windows command used to determine open
files.
Nbstat -c - Answer-A command used to display the NetBIOS
name table cache in Windows and active TCP (or UDP)
connections, as well as a host of other statistics.
,Microsoft Security ID - Answer-Refers to a unique identification
number that Microsoft assigns to a Windows user account for
granting the user access to a particular resource.
Wevtutil - Answer-This tool enables you to retrieve information
about event logs and publishers. You can also use this
command to install and uninstall event manifests; to run
queries; and to export, archive, and clear logs.
Commands for showing Windows Processes - Answer-Pslist
Tasklist
Listdlls
Handle
Shellbags - Answer-Contains user-specific Windows OS folder
and viewing preferences to Windows Explorer. It can tell us
which folders were accessed on the local machine, network,
and/or removable devices, and when.
BagMRU - Answer-Based on the keys that are here, you can tell
which directories were opened/closed during a time period.
, CustomDestinations Jump List - Answer-These files are created
when a user pins a file or an application to the taskbar.
There are also AutomaticDestinations which are just files
created by the Windows OS.
dmesg - Answer-Displays the contents of the kernel ring buffer.
Three Tiers of Log Management - Answer-Log Generation
Log Monitoring
Log Analysis/Storage
Postmortem Analysis - Answer-A type of log analysis to
investigate an incident that has already happened. The
alternative would be Real-time analysis which is analysis of an
ongoing attack.
A case involving a noncriminal matter such as a contract
dispute or a claim of patent infringement between two parties.
Answer- Civil Case