WGU C702 FORENSICS AND NETWORK INTRUSION CORE
EXAM MANUAL QUESTIONS AND ANSWERS RATED A+
✔✔Which path should a forensic investigator use to look for system logs in a Mac?
A /var/log/cups/access_log
B /var/log/
C /var/audit/
D /var/log/install.log - ✔✔B
✔✔Which tool should a forensic investigator use to view information from Linux kernel
ring buffers?
A arp
B dmesg
C fsck
D grep - ✔✔B
✔✔A forensic investigator makes a bit-stream copy of a Windows hard drive that has
been reformatted. The investigator needs to locate only the Adobe PDF files on the hard
drive.
Which tool should this investigator use?
A Quick Recovery
B Handy Recovery
C EaseUS Data Recovery
D Stellar Data Recovery - ✔✔C
✔✔Which hexadecimal value should an investigator search for to find JPEG images on
a device?
A 0x424D
B 0xD0CF11E0A1B11AE1
C 0x504B030414000600
D 0xFFD8 - ✔✔D
✔✔Which type of steganography allows the user to physically move a file but keep the
associated files in their original location for recovery?
A Whitespace
B Folder
C Image
D Web - ✔✔B
,✔✔An employee steals a sensitive text file by embedding it into a PNG file. The
employee then sends this file via an instant chat message to an accomplice.
Which type of steganography did this employee use?
A Document
B Image
C Text
D Web - ✔✔B
✔✔Which method is used when an investigator has access to the plaintext and an
image file with the hidden information?
A Stego-only
B Known-stego
C Known-message
D Chosen-message - ✔✔C
✔✔Which method is used when an investigator takes a plaintext message, uses various
tools against it, and finds the algorithm used to hide information?
A Stego-only
B Known-stego
C Known-message
D Chosen-message - ✔✔D
✔✔Which operating system is targeted by the DaveGrohl password cracker?
A Linux
B OS X
C UNIX
D Windows - ✔✔B
✔✔Which password cracker is used to recover passwords on an OS X operating
system?
A Cain and Abel
B DaveGrohl
C L0phtCrack
D Ophcrack - ✔✔B
✔✔Which tool allows a forensic investigator to process Transmission Control Protocol
(TCP) streams for analysis of malicious traffic?
A Kibana
,B OSSEC
C Syslog-ng
D Wireshark - ✔✔D
✔✔Which tool allows an investigator to review or process information in a Windows
environment but does not rely on the Windows API?
A EnCase
B netstat
C dd
D LogMeister - ✔✔A
✔✔A computer forensic investigator finds an unauthorized wireless access point
connected to an organization's network switch. This access point's wireless network has
a random name with a hidden service set identifier (SSID).
What is this set-up designed to do?
A Create a backdoor that a perpetrator can use by connecting wirelessly to the network
B Jam the wireless signals to stop all legitimate traffic from using the wireless network
C Activate the wireless cards in the laptops of victims to gain access to their data and
network
D Transmit high-power signals that force users to connect to the rogue wireless network
- ✔✔A
✔✔Which web-based application attack corrupts the execution stack of a web
application?
A Buffer overflow
B Cookie poisoning
C SQL injection
D Denial-of-service - ✔✔A
✔✔An employee is accused of sending a threatening email through Microsoft
Exchange.
Which file extension should the investigator search for to find the archived message on
the server?
A .DB
B .NSF
C .PST
D .EDB - ✔✔D
, ✔✔Investigators do not have physical access to the computer of the victim of an email
crime.
Which task should these investigators instruct the victim to perform in order to identify
the sending email server?
A Provide the email body
B Provide the email header
C Run Aid4Mail Email Forensics
D Run Email Address Verifier - ✔✔B
✔✔Which tool should a forensic investigator use on a Windows computer to locate all
the data on a computer disk, protect evidence, and create evidentiary reports for use in
legal proceedings?
A Wireshark
B OmniPeek
C ProDiscover
D Capsa - ✔✔C
✔✔What is the purpose of hashing tools during data acquisition?
A Dumping the original RAM contents to a forensically sterile removable device
B Enabling write protection on the original media to preserve the original evidence
C Validating the collected digital evidence by comparing the original and copied file
message digests
D Creating a replica of the original source to prevent the inadvertent alteration of the
original - ✔✔C
✔✔Which software-based tool is used to prevent writes to storage devices on a
computer?
A CRU WiebeTech
B ILook Investigator
C SAFE Block
D USB WriteBlocker - ✔✔C
✔✔Which tool should a forensic team use to research unauthorized changes in a
database?
A ApexSQL DBA
B Gargoyle Investigator Forensic Pro
C LSASecretsView
D RSA NetWitness Investigator - ✔✔A
EXAM MANUAL QUESTIONS AND ANSWERS RATED A+
✔✔Which path should a forensic investigator use to look for system logs in a Mac?
A /var/log/cups/access_log
B /var/log/
C /var/audit/
D /var/log/install.log - ✔✔B
✔✔Which tool should a forensic investigator use to view information from Linux kernel
ring buffers?
A arp
B dmesg
C fsck
D grep - ✔✔B
✔✔A forensic investigator makes a bit-stream copy of a Windows hard drive that has
been reformatted. The investigator needs to locate only the Adobe PDF files on the hard
drive.
Which tool should this investigator use?
A Quick Recovery
B Handy Recovery
C EaseUS Data Recovery
D Stellar Data Recovery - ✔✔C
✔✔Which hexadecimal value should an investigator search for to find JPEG images on
a device?
A 0x424D
B 0xD0CF11E0A1B11AE1
C 0x504B030414000600
D 0xFFD8 - ✔✔D
✔✔Which type of steganography allows the user to physically move a file but keep the
associated files in their original location for recovery?
A Whitespace
B Folder
C Image
D Web - ✔✔B
,✔✔An employee steals a sensitive text file by embedding it into a PNG file. The
employee then sends this file via an instant chat message to an accomplice.
Which type of steganography did this employee use?
A Document
B Image
C Text
D Web - ✔✔B
✔✔Which method is used when an investigator has access to the plaintext and an
image file with the hidden information?
A Stego-only
B Known-stego
C Known-message
D Chosen-message - ✔✔C
✔✔Which method is used when an investigator takes a plaintext message, uses various
tools against it, and finds the algorithm used to hide information?
A Stego-only
B Known-stego
C Known-message
D Chosen-message - ✔✔D
✔✔Which operating system is targeted by the DaveGrohl password cracker?
A Linux
B OS X
C UNIX
D Windows - ✔✔B
✔✔Which password cracker is used to recover passwords on an OS X operating
system?
A Cain and Abel
B DaveGrohl
C L0phtCrack
D Ophcrack - ✔✔B
✔✔Which tool allows a forensic investigator to process Transmission Control Protocol
(TCP) streams for analysis of malicious traffic?
A Kibana
,B OSSEC
C Syslog-ng
D Wireshark - ✔✔D
✔✔Which tool allows an investigator to review or process information in a Windows
environment but does not rely on the Windows API?
A EnCase
B netstat
C dd
D LogMeister - ✔✔A
✔✔A computer forensic investigator finds an unauthorized wireless access point
connected to an organization's network switch. This access point's wireless network has
a random name with a hidden service set identifier (SSID).
What is this set-up designed to do?
A Create a backdoor that a perpetrator can use by connecting wirelessly to the network
B Jam the wireless signals to stop all legitimate traffic from using the wireless network
C Activate the wireless cards in the laptops of victims to gain access to their data and
network
D Transmit high-power signals that force users to connect to the rogue wireless network
- ✔✔A
✔✔Which web-based application attack corrupts the execution stack of a web
application?
A Buffer overflow
B Cookie poisoning
C SQL injection
D Denial-of-service - ✔✔A
✔✔An employee is accused of sending a threatening email through Microsoft
Exchange.
Which file extension should the investigator search for to find the archived message on
the server?
A .DB
B .NSF
C .PST
D .EDB - ✔✔D
, ✔✔Investigators do not have physical access to the computer of the victim of an email
crime.
Which task should these investigators instruct the victim to perform in order to identify
the sending email server?
A Provide the email body
B Provide the email header
C Run Aid4Mail Email Forensics
D Run Email Address Verifier - ✔✔B
✔✔Which tool should a forensic investigator use on a Windows computer to locate all
the data on a computer disk, protect evidence, and create evidentiary reports for use in
legal proceedings?
A Wireshark
B OmniPeek
C ProDiscover
D Capsa - ✔✔C
✔✔What is the purpose of hashing tools during data acquisition?
A Dumping the original RAM contents to a forensically sterile removable device
B Enabling write protection on the original media to preserve the original evidence
C Validating the collected digital evidence by comparing the original and copied file
message digests
D Creating a replica of the original source to prevent the inadvertent alteration of the
original - ✔✔C
✔✔Which software-based tool is used to prevent writes to storage devices on a
computer?
A CRU WiebeTech
B ILook Investigator
C SAFE Block
D USB WriteBlocker - ✔✔C
✔✔Which tool should a forensic team use to research unauthorized changes in a
database?
A ApexSQL DBA
B Gargoyle Investigator Forensic Pro
C LSASecretsView
D RSA NetWitness Investigator - ✔✔A