2026/2027 | 66 QUESTIONS AND COMPLETE SOLUTIONS | ALREADY GRADED A+ | 100%
VERIFIED
Western Governors University (WGU) C702 Objective Assessment | Core Domains: Digital Forensics
Fundamentals, Network Intrusion Detection & Prevention, Incident Response Processes, Evidence
Collection & Preservation, Log Analysis, Malware & Attack Vectors, Network Traffic Analysis, Legal &
Ethical Considerations, Cybersecurity Frameworks, and Risk Mitigation Strategies |
Competency-Aligned Structure | Exam-Ready Format
Exam Structure
The WGU C702 objective final examination commonly consists of:
● 66 multiple-choice questions
● Single-best-answer format
● Scenario-based and application-focused cybersecurity items
Introduction
This WGU C702 Forensics and Network Intrusion Final Exam format for the 2026/2027 cycle reflects the
standard objective assessment structure used by Western Governors University. It emphasizes applied
digital forensics, network intrusion analysis, incident response decision-making, legal defensibility of
evidence handling, and professional cybersecurity practices within enterprise environments.
Answer Format
All correct answers must be presented in bold and green, followed by concise, well-defined rationales
explaining technical reasoning, security implications, investigative accuracy, and why alternative
responses are less appropriate.
1. Which of the following best describes the primary goal of digital forensics?
A. To delete malicious files from a system
B. To prevent future cyberattacks
C. To identify, preserve, analyze, and present digital evidence in a legally admissible
manner
D. To patch system vulnerabilities
, Digital forensics focuses on the systematic investigation of digital devices to recover and analyze
evidence that can be used in legal proceedings. Prevention, patching, and deletion are part of
cybersecurity operations, not forensic objectives.
2. During a forensic investigation, why is it critical to use a write blocker when acquiring
data from a suspect drive?
A. To speed up the imaging process
B. To compress the data for easier storage
C. To prevent alteration of the original evidence
D. To encrypt the suspect’s data
A write blocker ensures that no data is written to the original drive during acquisition, preserving its
integrity and maintaining the chain of custody—essential for legal admissibility.
3. Which forensic term refers to the ability to prove that evidence has not been altered
since collection?
A. Authenticity
B. Confidentiality
C. Integrity
D. Availability
Integrity ensures that evidence remains unchanged from the time it is collected until it is presented in
court. This is maintained through hashing, write blockers, and chain-of-custody documentation.
4. What is the first step in the incident response process according to NIST SP 800-61?
A. Eradication
B. Recovery
C. Preparation
, D. Identification
NIST defines six phases: Preparation, Identification, Containment, Eradication, Recovery, and
Post-incident activity. Preparation includes developing plans, training staff, and acquiring
tools—critical before an incident occurs.
5. Which protocol is commonly analyzed to detect command-and-control (C2) traffic in
network forensics?
A. HTTP/2
B. DNSSEC
C. DNS
D. FTPS
Malware often uses DNS tunneling or unusual DNS queries to communicate with C2 servers. DNS is
stateless and less monitored, making it a common vector for covert data exfiltration and beaconing.
6. What is the purpose of hashing in digital forensics?
A. To compress forensic images
B. To encrypt sensitive evidence
C. To verify the integrity of data
D. To anonymize user data
Hashing (e.g., SHA-256) generates a unique fixed-size value for a data set. If the hash of the original
and copy match, the data has not been altered—proving integrity.
7. Which of the following is a legal consideration when conducting a forensic investigation
on a corporate-owned device?
A. The Fourth Amendment always applies
B. A warrant is required regardless of ownership