• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 77 pages
Exam (elaborations)

APPROVED WGU D829/WGU D829 DIGITAL FORENSICS PERFORMANCE ASSESSMENT | COMPLETE INCIDENT REPORT AND UNAUTHORIZED ACTIVITY ANALYSIS ACTUAL EXAM COMPLETE AND ACCURATE EXAM QUESTIONS AND CORRECT VERIFIED ANSWERS CURRENTLY UPDATED EXAM VERSIO

Document preview thumbnail
Preview 4 out of 77 pages

APPROVED WGU D829/WGU D829 DIGITAL FORENSICS PERFORMANCE ASSESSMENT | COMPLETE INCIDENT REPORT AND UNAUTHORIZED ACTIVITY ANALYSIS ACTUAL EXAM COMPLETE AND ACCURATE EXAM QUESTIONS AND CORRECT VERIFIED ANSWERS CURRENTLY UPDATED EXAM VERSION 2026 |FULL REVISED EXAM |GUARANTEED PASS A+ |INSTANT DOWNLOAD PDF

Content preview

APPROVED WGU D829/WGU D829 DIGITAL FORENSICS
PERFORMANCE ASSESSMENT | COMPLETE INCIDENT
REPORT AND UNAUTHORIZED ACTIVITY ANALYSIS
ACTUAL EXAM 2026-2027 COMPLETE AND ACCURATE
EXAM QUESTIONS AND CORRECT VERIFIED ANSWERS
CURRENTLY UPDATED EXAM VERSION 2026 |FULL
REVISED EXAM |GUARANTEED PASS A+ |INSTANT
DOWNLOAD PDF



A digital forensic investigator arrives at the scene of a security incident involving a
live, running computer system. According to standard forensic best practices, what
is the most appropriate initial action regarding the system's power state?
A. Immediately pull the power cable from the system to prevent data loss.
B. Document the system state and consider the acquisition of volatile data.
C. Log in using the suspect's credentials to assess the active session.
D. Shut down the system using the operating system's normal shutdown procedure.


Answer: B
Rationale: The investigator should first document the system, assess the situation,
and preserve volatile data where authorized and appropriate, as volatile data like
memory contents and running processes can be lost when power is removed.
Pulling the power cable can cause data loss and is not the preferred first step;

,proper forensic procedures prioritize the acquisition of volatile evidence before any
other action. Logging into the system would alter the state of the evidence, and a
normal shutdown can also alter critical files and volatile data.


Which of the following best describes the primary purpose of a cryptographic hash
function in the context of digital forensics?
A. To encrypt the original evidence, preventing unauthorized access.
B. To generate a unique digital fingerprint of a piece of evidence to verify its
integrity.
C. To compress large files for more efficient storage of forensic images.
D. To recover the original data from a deleted file on a hard drive.


Answer: B
Rationale: A cryptographic hash function maps a variable-length string or message
to a fixed-size value, or message digest . This hash serves as a unique fingerprint;
any alteration to the original data, even a single bit, will result in a completely
different hash value. This is crucial for non-repudiation and to ensure that the
evidence has not been modified during the collection, preservation, and analysis
process .


What is an Indicator of Compromise (IOC) in the context of incident response?
A. A guaranteed proof that an employee has committed misconduct.
B. Artifacts observed on a network or operating system that suggest a possible
security breach.
C. A formal document that lists all the hardware replaced after an incident.
D. A legal requirement for an organization to report a data breach to authorities.

,Answer: B
Rationale: An IOC is evidence suggesting possible malicious activity, which can
include suspicious IP addresses, domain names, file hashes, registry keys, unusual
processes, and abnormal account activity . They are used to identify potential
compromises, but they are not by themselves absolute proof of an incident; they
signal that further investigation is warranted.


What is the primary objective of the "containment" phase of the incident response
process?
A. To completely remove the root cause of the incident from the environment.
B. To restore systems to normal operation and monitor for any recurring issues.
C. To limit the damage caused by the incident and prevent it from spreading.
D. To conduct a thorough analysis to identify the attacker's techniques and
motivations.


Answer: C
Rationale: The primary objective of containment is to limit the damage caused by
an incident and prevent it from spreading . An example of short-term containment
is isolating an affected endpoint from the network to stop lateral movement and
prevent further communication with malicious infrastructure .


When analyzing Windows Event Logs, which Event ID commonly indicates a
successful logon attempt by a user?
A. 4625
B. 4624
C. 1102
D. 4688

, Answer: B
Rationale: Event ID 4624 generally indicates a successful account logon . Event ID
4625, on the other hand, typically records failed authentication attempts . Event ID
1102 indicates that the security audit log was cleared, and Event ID 4688 is used
for process creation.


A forensic investigator observes a sequence of events in the Windows Security log:
dozens of failed logon attempts (Event ID 4625) from a single source, followed
immediately by a single successful logon (Event ID 4624). What type of attack
does this pattern most likely indicate?
A. A distributed denial-of-service (DDoS) attack.
B. A routine backup process running on the system.
C. A possible brute-force or password-spraying attack.
D. An attempt by a user to access a file they do not have permission to open.


Answer: C
Rationale: Repeated failed attempts followed by success can indicate credential
guessing or password spraying . Attackers often use automated tools to try many
passwords against a single account or try common passwords against many
accounts until they find one that works, resulting in this log pattern.


Which of the following is an example of a standard forensic tool used for creating
forensic images of hard drives, partitions, and files?
A. Wireshark
B. Metasploit
C. FTK Imager

Document information

Uploaded on
August 31, 2026
Number of pages
77
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$23.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
9
Followers
2
Items
546
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions