Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 30 pages
Exam (elaborations)

Title: WGU Master’s Course C702 – Forensics and Network Intrusion Complete Solutions and Study Material

Document preview thumbnail
Preview 3 out of 30 pages

This document contains the full set of solutions and study material for WGU Master’s Course C702: Forensics and Network Intrusion. It covers essential digital forensics methodologies, network intrusion detection, evidence collection, incident response, and analysis of cyberattacks. The complete solution set provides detailed explanations and practical examples, helping students fully understand course assessments and prepare for related cybersecurity certifications.

Content preview

WGU Master’s Course C702 – Forensics and Network Intrusion
Complete Solutions and Study Material

Question 1:
According to NIST SP 800-86, what is the primary goal of the collection phase in digital
forensics?
A) Analyze extracted data for patterns
B) Identify, acquire, and protect original data
C) Generate a final report for stakeholders

D) Validate tools against known datasets

Correct Answer: B

Explanation: NIST SP 800-86 outlines four phases: collection (identify/acquire/protect data),
examination, analysis, and reporting. Collection ensures evidence integrity before analysis,
preventing alteration.

Question 2:
In the EC-Council CHFI model, what distinguishes "dead" from "live" acquisition?
A) Dead uses powered-off systems; live captures volatile data from running systems
B) Dead analyzes network traffic; live focuses on disk imaging
C) Dead requires write-blockers; live uses software only

D) Dead is for mobile devices; live for desktops

Correct Answer: A

Explanation: CHFI v10 emphasizes dead acquisition for non-volatile data (e.g., HDD imaging)
and live for volatile artifacts (e.g., RAM), balancing completeness with system stability.

Question 3:
Which principle from ISO 27037 ensures forensic readiness?
A) Prioritizing speed over accuracy
B) Establishing processes for identification, collection, and preservation
C) Ignoring chain of custody for internal audits

D) Using unverified tools for initial triage

Correct Answer: B

Explanation: ISO 27037 (Guidelines for digital evidence) mandates proactive processes to
handle evidence from identification to presentation, ensuring admissibility.

,Question 4:
A forensic investigator encounters encrypted data during an initial scan. Per NIST guidelines,
what should they do first?
A) Attempt decryption with default passwords
B) Document the encryption and seek legal authority for keys
C) Delete the data to avoid bias

D) Proceed to analysis without documentation

Correct Answer: B

Explanation: NIST SP 800-86 requires documenting obstacles like encryption and obtaining
warrants to maintain legal integrity, preventing unauthorized access.

Question 5:
What is the role of hashing (e.g., MD5/SHA-256) in forensic fundamentals?
A) To compress evidence files
B) To verify data integrity during acquisition
C) To search for keywords

D) To encrypt reports

Correct Answer: B

Explanation: Hashing creates a unique fingerprint; pre- and post-acquisition comparisons
confirm no tampering, a core NIST/CHFI integrity check.

Question 6:
In a corporate investigation, what forensic principle applies to employee devices?
A) Unlimited access without consent
B) Consent and scope limited to policy violations
C) Mandatory imaging of all personal data

D) Deletion of irrelevant files

Correct Answer: B

Explanation: CHFI stresses legal consent and scoped searches to avoid privacy violations,
aligning with ethical standards like those from ISFCE.

Question 7:
NIST defines digital forensics as integrating techniques into what?
A) Routine backups
B) Incident response
C) Software development

, D) Hardware maintenance

Correct Answer: B

Explanation: SP 800-86 integrates forensics into IR to enhance detection, analysis, and
recovery from security incidents.

Question 8:
What is a key challenge in mobile forensics per CHFI?
A) Infinite storage
B) Rapid OS updates and encryption
C) Lack of volatility

D) Overly simple file systems

Correct Answer: B

Explanation: CHFI v10 highlights frequent updates (e.g., iOS/Android) complicating tool
compatibility and encryption (e.g., FBE) hindering access.

Question 9:
Which NIST phase involves timeline reconstruction?
A) Collection
B) Examination
C) Analysis

D) Reporting

Correct Answer: C

Explanation: Analysis correlates events via timestamps/logs, deriving insights like attack
sequences from raw data.

Question 10:
Ethical forensics requires what during tool selection?
A) Cost over validation
B) NIST CFTT-tested tools
C) Open-source only

D) Vendor recommendations alone

Correct Answer: B

Explanation: NIST Computer Forensics Tool Testing (CFTT) ensures reliability; unvalidated
tools risk inadmissible evidence.

Module 2: Evidence Acquisition and Preservation (12 Questions)

Document information

Uploaded on
October 16, 2025
Number of pages
30
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$11.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
2
Followers
0
Items
47
Last sold
4 months ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions