WGU C840 – DIGITAL FORENSICS IN CYBERSECURITY WITH
CORRECT ANSWERS AND RATIONALES 2026/2027 VERSION
1. What is the primary goal of digital forensics?
A. To improve computer performance
B. To identify, preserve, analyze, and report digital evidence
C. To create new software
D. To prevent all cyberattacks
Correct Answer: B. To identify, preserve, analyze, and report digital evidence
Rationale: Digital forensics involves the systematic examination of digital evidence to support
investigations.
2. What is the first priority when handling potential digital evidence?
A. Modify the evidence for easier analysis
B. Preserve its integrity
C. Delete irrelevant files
D. Connect the device to the internet
Correct Answer: B. Preserve its integrity
Rationale: Evidence must be protected from alteration or contamination.
3. What does the chain of custody document?
A. Computer performance
B. The history of evidence handling
C. Password complexity
D. Network bandwidth
Correct Answer: B. The history of evidence handling
Rationale: It documents the collection, transfer, storage, and handling of evidence.
4. Which principle is most important when acquiring digital evidence?
A. Change the original evidence to test it
B. Minimize changes to the original evidence
C. Open every file manually
D. Connect the evidence to public Wi-Fi
Correct Answer: B. Minimize changes to the original evidence
Rationale: Investigators should preserve the original evidence and work from verified forensic
copies.
,5. What is a forensic image?
A. A screenshot of a computer
B. A bit-by-bit copy of digital storage media
C. A photograph of a suspect
D. A compressed text file
Correct Answer: B. A bit-by-bit copy of digital storage media
Rationale: A forensic image attempts to capture the contents of storage, including deleted and
unallocated areas.
6. Why are hash values used in digital forensics?
A. To increase storage capacity
B. To verify evidence integrity
C. To recover passwords automatically
D. To improve processor speed
Correct Answer: B. To verify evidence integrity
Rationale: Matching hash values help demonstrate that evidence has not changed.
7. Which of the following is a cryptographic hash function?
A. SHA-256
B. FTP
C. DNS
D. HTTP
Correct Answer: A. SHA-256
Rationale: SHA-256 produces a fixed-length hash used for integrity verification.
8. What is the purpose of a write blocker?
A. Prevent writing to the original evidence media
B. Encrypt a hard drive
C. Delete malware
D. Increase disk speed
Correct Answer: A. Prevent writing to the original evidence media
Rationale: Write blockers help prevent accidental modification of evidence.
9. Which type of data is usually lost when a computer is powered off?
A. Volatile memory data
B. Files stored on a hard drive
, C. Archived documents
D. Backup files
Correct Answer: A. Volatile memory data
Rationale: RAM contains volatile information that may disappear when power is removed.
10. Which evidence should generally be collected first when appropriate?
A. Volatile data
B. Archived DVDs
C. Printed reports
D. Old backups
Correct Answer: A. Volatile data
Rationale: Volatile evidence, such as RAM contents, may disappear quickly.
11. Which of the following is an example of volatile data?
A. RAM contents
B. A printed document
C. A sealed DVD
D. A powered-off hard drive
Correct Answer: A. RAM contents
Rationale: RAM data is temporary and may be lost when power is removed.
12. What information may be found in memory forensics?
A. Running processes and network connections
B. Only deleted photographs
C. Printed documents
D. Physical fingerprints only
Correct Answer: A. Running processes and network connections
Rationale: Memory may contain active processes, credentials, connections, and other runtime
information.
13. What is the purpose of forensic triage?
A. Quickly determine relevant evidence and priorities
B. Destroy unnecessary evidence
C. Replace the investigation
D. Format all devices
Correct Answer: A. Quickly determine relevant evidence and priorities
Rationale: Triage helps investigators prioritize resources during an investigation.
CORRECT ANSWERS AND RATIONALES 2026/2027 VERSION
1. What is the primary goal of digital forensics?
A. To improve computer performance
B. To identify, preserve, analyze, and report digital evidence
C. To create new software
D. To prevent all cyberattacks
Correct Answer: B. To identify, preserve, analyze, and report digital evidence
Rationale: Digital forensics involves the systematic examination of digital evidence to support
investigations.
2. What is the first priority when handling potential digital evidence?
A. Modify the evidence for easier analysis
B. Preserve its integrity
C. Delete irrelevant files
D. Connect the device to the internet
Correct Answer: B. Preserve its integrity
Rationale: Evidence must be protected from alteration or contamination.
3. What does the chain of custody document?
A. Computer performance
B. The history of evidence handling
C. Password complexity
D. Network bandwidth
Correct Answer: B. The history of evidence handling
Rationale: It documents the collection, transfer, storage, and handling of evidence.
4. Which principle is most important when acquiring digital evidence?
A. Change the original evidence to test it
B. Minimize changes to the original evidence
C. Open every file manually
D. Connect the evidence to public Wi-Fi
Correct Answer: B. Minimize changes to the original evidence
Rationale: Investigators should preserve the original evidence and work from verified forensic
copies.
,5. What is a forensic image?
A. A screenshot of a computer
B. A bit-by-bit copy of digital storage media
C. A photograph of a suspect
D. A compressed text file
Correct Answer: B. A bit-by-bit copy of digital storage media
Rationale: A forensic image attempts to capture the contents of storage, including deleted and
unallocated areas.
6. Why are hash values used in digital forensics?
A. To increase storage capacity
B. To verify evidence integrity
C. To recover passwords automatically
D. To improve processor speed
Correct Answer: B. To verify evidence integrity
Rationale: Matching hash values help demonstrate that evidence has not changed.
7. Which of the following is a cryptographic hash function?
A. SHA-256
B. FTP
C. DNS
D. HTTP
Correct Answer: A. SHA-256
Rationale: SHA-256 produces a fixed-length hash used for integrity verification.
8. What is the purpose of a write blocker?
A. Prevent writing to the original evidence media
B. Encrypt a hard drive
C. Delete malware
D. Increase disk speed
Correct Answer: A. Prevent writing to the original evidence media
Rationale: Write blockers help prevent accidental modification of evidence.
9. Which type of data is usually lost when a computer is powered off?
A. Volatile memory data
B. Files stored on a hard drive
, C. Archived documents
D. Backup files
Correct Answer: A. Volatile memory data
Rationale: RAM contains volatile information that may disappear when power is removed.
10. Which evidence should generally be collected first when appropriate?
A. Volatile data
B. Archived DVDs
C. Printed reports
D. Old backups
Correct Answer: A. Volatile data
Rationale: Volatile evidence, such as RAM contents, may disappear quickly.
11. Which of the following is an example of volatile data?
A. RAM contents
B. A printed document
C. A sealed DVD
D. A powered-off hard drive
Correct Answer: A. RAM contents
Rationale: RAM data is temporary and may be lost when power is removed.
12. What information may be found in memory forensics?
A. Running processes and network connections
B. Only deleted photographs
C. Printed documents
D. Physical fingerprints only
Correct Answer: A. Running processes and network connections
Rationale: Memory may contain active processes, credentials, connections, and other runtime
information.
13. What is the purpose of forensic triage?
A. Quickly determine relevant evidence and priorities
B. Destroy unnecessary evidence
C. Replace the investigation
D. Format all devices
Correct Answer: A. Quickly determine relevant evidence and priorities
Rationale: Triage helps investigators prioritize resources during an investigation.