• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 61 pages
Exam (elaborations)

WGU C702 Forensics and Network Intrusion 2026/2027 | Western Governors University C702 Master's Course Study Guide, Exam Prep, Computer Forensics, Network Intrusion, Digital Evidence, Disk & File System Forensics, Operating System Forensics, Device

Document preview thumbnail
Preview 4 out of 61 pages

WGU C702 Forensics and Network Intrusion 2026/2027 | Western Governors University master's-level course study and exam-preparation resource covering the core concepts of digital forensics and network intrusion. Topics include computer forensics fundamentals, digital evidence, media forensics, hard disks and storage devices, file-system forensics, operating-system forensics, data recovery, device forensics, network intrusion detection, audits, investigations, evidence handling and cybersecurity incident analysis. This resource is designed to help WGU students organize their C702 study, review important concepts, and prepare through practice-focused questions, explanations and exam preparation. WGU's course description identifies C702 as Forensics and Network Intrusion and emphasizes detecting hacking attacks, extracting evidence, reporting cybercrime and conducting audits to help prevent future attacks.

Content preview

WGU C702 Forensics and Network Intrusion 2026/2027 | Western
Governors University C702 Master's Course Study Guide, Exam
Prep, Computer Forensics, Network Intrusion, Digital Evidence,
Disk & File System Forensics, Operating System Forensics,
Device Forensics, Audits, Investigations, Cybersecurity Practice
Questions & Answers
Question 1: A hospital’s security team discovers that a former employee
accessed patient records after termination. Law enforcement is notified and a
prosecutor files charges. Which category of investigation does this represent?
A. Administrative
B. Civil
C. Criminal
D. Regulatory
CORRECT ANSWER: C. Criminal
Rationale: A criminal investigation is initiated by law enforcement in response to a
suspected violation of criminal law, such as unauthorized access to protected
health information. Administrative investigations involve internal policy
violations, civil investigations involve disputes between private parties seeking
damages, and regulatory investigations involve government agency compliance
enforcement.
Question 2: Which principle states that a forensic examiner must not continue
an investigation if it exceeds their knowledge or skill level?
A. Locard’s Exchange Principle
B. Chain of Custody
C. Competency Boundary
D. Best Evidence Rule
CORRECT ANSWER: C. Competency Boundary
Rationale: The competency boundary principle requires forensic examiners to
acknowledge their limitations and not proceed with examinations beyond their
expertise. This ensures the integrity of the investigation and prevents inaccurate
or inadmissible findings.

,Question 3: What is the primary purpose of maintaining a chain of custody
document?
A. To record the cost of evidence storage
B. To document the chronological history of evidence possession and control
C. To identify the suspect in a criminal case
D. To summarize the investigator’s conclusions
CORRECT ANSWER: B. To document the chronological history of evidence
possession and control
Rationale: A chain of custody provides an unbroken record of who handled
evidence, when, and for what purpose. This documentation establishes that
evidence has not been tampered with or compromised, making it admissible in
court.
Question 4: An investigator arrives at a crime scene where a computer is
powered on and running. What is the FIRST action the investigator should take?
A. Immediately power off the computer
B. Photograph the screen and capture volatile data
C. Disconnect the computer from the network
D. Remove the hard drive for imaging
CORRECT ANSWER: B. Photograph the screen and capture volatile data
Rationale: When a computer is powered on, volatile data such as RAM contents,
running processes, and network connections exist only while power is
maintained. The first responder should document the current state and capture
volatile data before any action that might alter or destroy it.
Question 5: Which type of cybercrime investigation involves a dispute between
two private parties seeking monetary damages?
A. Administrative
B. Criminal
C. Civil
D. Internal
CORRECT ANSWER: C. Civil

,Rationale: Civil investigations arise from disputes between private parties, such as
breach of contract or intellectual property disputes, where the remedy sought is
typically monetary damages rather than criminal prosecution.
Question 6: What is the correct order of volatility for digital evidence, from
most volatile to least volatile?
A. Hard drive, RAM, network connections, cache
B. RAM, cache, network connections, hard drive
C. Network connections, RAM, cache, hard drive
D. Cache, network connections, RAM, hard drive
CORRECT ANSWER: B. RAM, cache, network connections, hard drive
Rationale: The order of volatility dictates that the most volatile data should be
collected first. RAM and processor cache lose their contents when power is
removed. Network connections and running processes are next, followed by non-
volatile storage such as hard drives.
Question 7: Which term describes temporary information on a device that
requires constant power to persist?
A. Non-volatile data
B. Persistent data
C. Volatile data
D. Archived data
CORRECT ANSWER: C. Volatile data
Rationale: Volatile data exists only while the system has power. Examples include
RAM contents, running processes, and open network connections. Once power is
lost, this data is irretrievable, making its capture a priority in forensic
investigations.
Question 8: What is the primary function of a write blocker in digital forensics?
A. To encrypt evidence during transport
B. To prevent any modification of the source drive during imaging
C. To increase data transfer speed
D. To compress forensic images

, CORRECT ANSWER: B. To prevent any modification of the source drive during
imaging
Rationale: A write blocker is a hardware or software tool that allows read-only
access to a storage device, ensuring that the forensic imaging process does not
alter the original evidence in any way.
Question 9: Which hashing algorithm is commonly used to verify the integrity of
forensic images?
A. AES-256
B. MD5
C. RSA
D. DES
CORRECT ANSWER: B. MD5
Rationale: MD5 (Message Digest Algorithm 5) produces a 128-bit hash value
commonly used in digital forensics to verify that a forensic image is an exact
duplicate of the original evidence. Any change to the data would produce a
different hash value.
Question 10: What is the goal of forensic science in the context of digital
investigations?
A. To recover deleted files for personal use
B. To determine the evidential value of the crime scene and related evidence
C. To install security software on compromised systems
D. To monitor network traffic in real time
CORRECT ANSWER: B. To determine the evidential value of the crime scene and
related evidence
Rationale: The goal of forensic science is to identify, preserve, analyze, and
present evidence in a manner that establishes its relevance and reliability for legal
proceedings. This applies equally to digital evidence.
Question 11: Which type of investigation is conducted internally by an
organization to determine if employees are following company policies?

Document information

Uploaded on
September 18, 2026
Number of pages
61
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
ruthmuthoni
2.7
(3)
Sold
539
Followers
1
Items
1106
Last sold
20 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions