Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 22 pages
Exam (elaborations)

WGU D431 OA Exam 119 Questions with Verified Answers,100%CORRECT

Document preview thumbnail
Preview 3 out of 22 pages

WGU D431 OA Exam 119 Questions with Verified Answers The process of acquiring and analyzing information stored on physical storage media, such as computer hard drives, smartphones, GPS systems, and removable media. Includes both the recovery of hidden and deleted information and the process of identifying who created a file or message. - CORRECT ANSWER Disk Forensics The study of the source and content of email as evidence, including the identification of the sender, recipient, date, time, and origination location of an email message. - CORRECT ANSWER Email Forensics the process of examining network traffic, including transaction logs and real-time monitoring using sniffers and tracing. - CORRECT ANSWER Network Forensics is the process of piecing together where and when a user has been on the internet. For example, you can use internet forensics to determine whether inappropriate internet content access and downloading were accidental. - CORRECT ANSWER Internet Forensics also known as malware forensics, is the process of examining malicious computer code - CORRECT ANSWER Software Forensics The process of searching memory in real time, typically for working with compromised hosts or to identify system abuse. - CORRECT ANSWER Live system forensics

Content preview

WGU D431 OA Exam 119 Questions with Verified
Answers


The process of acquiring and analyzing information stored on physical storage
media, such as computer hard drives, smartphones, GPS systems, and removable
media. Includes both the recovery of hidden and deleted information and the
process of identifying who created a file or message. - CORRECT ANSWER Disk
Forensics


The study of the source and content of email as evidence, including the
identification of the sender, recipient, date, time, and origination location of an
email message. - CORRECT ANSWER Email Forensics


the process of examining network traffic, including transaction logs and real-time
monitoring using sniffers and tracing. - CORRECT ANSWER Network Forensics


is the process of piecing together where and when a user has been on the
internet. For example, you can use internet forensics to determine whether
inappropriate internet content access and downloading were accidental. -
CORRECT ANSWER Internet Forensics


also known as malware forensics, is the process of examining malicious computer
code - CORRECT ANSWER Software Forensics


The process of searching memory in real time, typically for working with
compromised hosts or to identify system abuse. - CORRECT ANSWER Live system
forensics

,is the process of searching the contents of cell phones. A few years ago, this was
just not a big issue, but with the ubiquitous nature of cell phones today, cell-
phone
forensics is a very important topic. A cell phone can be a treasure trove of
evidence. Modern
cell phones are essentially computers with processors, memory, even hard drives
and operating
systems, and they operate on networks. Phone forensics also includes VoIP and
traditional phones and may overlap the Foreign Intelligence Surveillance Act of
1978 (FISA), the USA
PATRIOT Act, and the Communications Assistance for Law Enforcement Act
(CALEA) in the United States. - CORRECT ANSWER Cell-Phone Forensics


From the time the evidence is first seized by a law
enforcement officer or civilian investigator until the moment it is shown in court,
the whereabouts and custody of the evidence, and how it was handled and stored
and by whom, must be able to be shown at all times. Failure to maintain the
proper chain of custody can lead to evidence being excluded from trial. - CORRECT
ANSWER Chain of Custody


One very important principle is to touch the system as little as possible. It is
possible to make changes to the system in the process of examining it, which is
very undesirable. Obviously, you have to interact with the system to investigate it.
The answer is to make a forensic copy and work with that copy. You can make a
forensic copy with most major forensic tools such as AccessData's Forensic Toolkit,
Guidance Software's EnCase, or PassMark's OSForensics. There are also open
source software products that allow copying of original source information. To be

, specific, make a copy and analyze the copy. - CORRECT ANSWER Don't Touch the
Suspect Drive


The next issue is documentation. The rule is that you document everything. Who
was present when the device was seized? What was connected to the device or
showing on the screen when you seized it? What specific tools and techniques did
you use? Who had access to the evidence from the time of seizure until the time
of trial? All of this must be documented. And when in doubt, err on the side of
over-documentation. It really is not possible to document too much information
about an investigation. - CORRECT ANSWER Document trail


It is absolutely critical to the integrity of your investigation as well as to
maintaining the chain of custody that you secure the evidence. It is common to
have the forensic lab be a locked room with access given only to those who must
enter. Then, evidence is usually secured in a safe, with access given out only on a
need-to-know basis. You have to take every reasonable precaution to ensure that
no one can tamper with the evidence. - CORRECT ANSWER Secure the Evidence


Standard used by a trial judge to make a preliminary assessment of whether an
expert's scientific testimony is based on reasoning or methodology that is
scientifically valid and can
properly be applied to the facts at issue. Under this standard, the factors that may
be considered in determining whether the methodology is valid are: (1) whether
the theory or
technique in question can be and has been tested; (2) whether it has been
subjected to peer
review and publication; (3) its known or potential error rate; (4) the existence and
maintenance

Document information

Uploaded on
July 24, 2025
Number of pages
22
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
paulhans
3.5
(136)
Sold
796
Followers
641
Items
7864
Last sold
2 weeks ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions