Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 200 pages
Exam (elaborations)

WGU MASTER'S COURSE C702 – FORENSICS AND NETWORK INTRUSION 350 UNIQUE MULTIPLE‑CHOICE QUESTIONS WITH CORRECT ANSWERS & DETAILED RATIONALES

Document preview thumbnail
Preview 4 out of 200 pages

Master the WGU Master's Course C702 – Forensics and Network Intrusion with this comprehensive collection of 350 expertly crafted multiple-choice questions and detailed rationales. This essential study guide covers every critical topic required for C702 success, including Computer Forensics Foundations (Locard's Exchange Principle, order of volatility, forensic imaging, hash values, chain of custody), Network Intrusion Detection and Analysis (DoS/DDoS attacks, IDS/IPS, packet analysis, TCP/IP fundamentals, wireless security), Evidence Collection and Preservation (write blockers, mobile forensics, volatile data, data carving, Windows Registry forensics), Incident Response (NIST framework, containment, eradication, recovery, malware analysis), and Legal and Ethical Considerations (search warrants, Federal Rules of Evidence, Daubert standard, expert testimony, privacy laws). Each question is designed to test your understanding of forensic methodologies, network security concepts, and legal frameworks. Perfect for WGU graduate students, cybersecurity professionals, forensic analysts, and anyone preparing for forensics certification or career advancement. The comprehensive rationales provide deep understanding of forensic principles, making this resource ideal for exam preparation and practical application in security operations. All content is aligned with WGU C702 course objectives and includes the latest best practices in digital forensics and incident response.

Content preview

WGU MASTER'S COURSE C702 – FORENSICS
AND NETWORK INTRUSION 350 UNIQUE
MULTIPLE‑CHOICE QUESTIONS WITH
CORRECT ANSWERS & DETAILED
RATIONALES


DOMAIN 1: DIGITAL FORENSICS FUNDAMENTALS (Qs 1–75)




Question 1
What is the primary goal of computer forensics?
A) To recover deleted files for personal data recovery
B) To identify, preserve, analyze, and present digital evidence in a legally
admissible manner
C) To monitor network traffic for active intrusions
D) To install security software on compromised systems


Correct Answer: B – To identify, preserve, analyze, and present digital evidence in
a legally admissible manner.
Rationale: Computer forensics is a structured investigation process with the
ultimate goal of ensuring findings are acceptable in a court of law. This involves a
methodological approach to handling evidence, distinguishing it from general data
recovery or network monitoring.



1

,---


Question 2
According to Locard's Exchange Principle, what occurs when someone enters a
crime scene?
A) The scene remains completely unchanged by the person's presence
B) Only physical trace evidence is transferred, never digital evidence
C) The person takes something from the scene and leaves something of themselves
behind
D) Nothing is transferred if the person is wearing protective gear


Correct Answer: C – The person takes something from the scene and leaves
something of themselves behind.
Rationale: Locard's principle is fundamental to forensics, stating that every contact
leaves a trace. In digital forensics, this translates to artifacts like log entries, file
modifications, and network connections left by an intruder.


---


Question 3
Which type of investigation involves a dispute between two parties, typically
resulting in monetary damages?
A) Criminal investigation
B) Civil investigation
C) Administrative investigation
D) Regulatory investigation



2

,Correct Answer: B – Civil investigation.
Rationale: Civil cases are non‑criminal disputes, such as contract violations or
lawsuits, where the outcome usually involves financial penalties for the liable
party, not imprisonment. Criminal cases involve government prosecution for
violations of law.


---


Question 4
An organization is investigating an employee for violating the company's
acceptable use policy. What type of investigation is this?
A) Criminal case
B) Civil case
C) Administrative case
D) Class‑action lawsuit


Correct Answer: C – Administrative case.
Rationale: Administrative cases are internal investigations focused on whether
employees are following organizational rules and policies. They are non‑criminal
in nature and do not involve law enforcement.


---


Question 5
What is the very first step a first responder must take upon arriving at a digital
crime scene?
A) Begin imaging the hard drives immediately
B) Interview all potential witnesses
3

, C) Secure and isolate the scene to prevent contamination of evidence
D) Power on all computers to check their status


Correct Answer: C – Secure and isolate the scene to prevent contamination of
evidence.
Rationale: The priority for a first responder is to secure the scene and preserve
evidence integrity. This prevents unauthorized access, alteration, or destruction of
volatile digital evidence.


---


Question 6
What is the main purpose of a hardware write blocker?
A) To prevent any data writes to the original evidence, preserving its integrity
B) To accelerate the data acquisition process
C) To decrypt encrypted files on the suspect drive
D) To create a backup of the operating system


Correct Answer: A – To prevent any data writes to the original evidence,
preserving its integrity.
Rationale: A hardware write blocker sits between the source drive and the forensic
workstation, intercepting and blocking any write commands. This ensures the
original evidence remains unaltered and forensically sound.


---


Question 7


4

Document information

Uploaded on
July 29, 2026
Number of pages
200
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$20.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NurseMitch
4.8
(101)
Sold
56
Followers
3
Items
1225
Last sold
2 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions