100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

WGU D431 Objective Assessment Review (Latest 2025/ 2026 Update) Digital Forensics in Cybersecurity| Qs & As| Grade A 100% Correct (Verified Answers)

Rating
-
Sold
-
Pages
26
Grade
A+
Uploaded on
31-12-2024
Written in
2024/2025

WGU D431 Objective Assessment Review (Latest 2025/ 2026 Update) Digital Forensics in Cybersecurity| Qs & As| Grade A 100% Correct (Verified Answers) Q: Which method of copying digital evidence ensures proper evidence collection? A. Make the copy at the bit-level B. Copy files using drag and drop C. Make the copy using file transfer D. Copy the logical partitions Answer: A. Make the copy at the bit-level Q: Which type of storage format should be transported in a special bag to reduce electrostatic interference? A. Solid-state drives B. Optical media C. Digital audio tapes D. Magnetic media Answer: A. Solid-state drives Q: Which Windows component is responsible for reading the file and displaying the boot loader menu on Windows XP during the boot process? A. NTLDR B. NTOSKRNL C. Windows Registry D. Win32 subsystem Answer: A. NTLDR Q: The following line of code is an example of how to make a forensic copy of a suspect drive: dd if=/dev/mem of=/evidence/y1 Which operating system should be used to run this command? A. Windows B. Chrome C. BlackBerry D. Linux Answer: D. Linux Q: Which file system is supported by Mac? A. Berkeley Fast File System (FFS) B. Extended File System (Ext) C. Reiser File System (ReiserFS) D. Hierarchical File System Plus (HFS+) Answer: D. Hierarchical File System Plus (HFS+) Q: Where are local passwords stored for the Windows operating system? A. SAM file in WindowsSystem32 B. SAM file in WindowsSecurity C. In the registry key HKEY_LOCAL_MACHINESYSTEM D. In the registry key HKEY_LOCAL_MAHCINESECURITY Answer: A. SAM file in WindowsSystem32 Q: Where on a Windows system is the config folder located that contains the SAM file? A. C:WindowsSystem32 B. C:WindowsSystemResources C. C:Program Files D. C:Users Answer: A. C:WindowsSystem32 Q: What should a forensic investigator use to gather the most reliable routing information for tracking an email message? A. Email header B. Email address C. Tracert D. Netstat Answer: A. Email header Q: A forensic examiner reviews a laptop running OS X which has been compromised. The examiner wants to know if there were any mounted volumes created from USB drives.

Show more Read less
Institution
WGU D436
Course
WGU D436










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
WGU D436
Course
WGU D436

Document information

Uploaded on
December 31, 2024
Number of pages
26
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

  • whic

Content preview

WGUlD431lObjectivelAssessmentlReviewl
(LatestlUpdate)lDigitallForensicslinl
Cybersecurity|lQsl&lAs|lGradelAl100%l
Correctl(VerifiedlAnswers)

Q:lWhichlmethodloflcopyingldigitallevidencelensureslproperlevidencelcollection?
A.lMakelthelcopylatlthelbit-level
B.lCopylfileslusingldraglandldrop
C.lMakelthelcopylusinglfileltransfer
D.lCopylthellogicallpartitions


Answer:
A.lMakelthelcopylatlthelbit-level




Q:lWhichltypeloflstoragelformatlshouldlbeltransportedlinlalspeciallbagltolreducelelectrostaticl
interference?

A.lSolid-stateldrives
B.lOpticallmedia
C.lDigitallaudioltapes
D.lMagneticlmedia


Answer:
A.lSolid-stateldrives




Q:lWhichlWindowslcomponentlislresponsiblelforlreadinglthelboot.inilfilelandldisplayinglthelb
ootlloaderlmenulonlWindowslXPlduringlthelbootlprocess?

,A.lNTLDR
B.lNTOSKRNL
C.lWindowslRegistry
D.lWin32lsubsystem


Answer:
A.lNTLDR




Q:lThelfollowingllineloflcodelislanlexampleloflhowltolmakelalforensiclcopyloflalsuspectldriv
e:l

ddlif=/dev/memlof=/evidence/image.memory1l

Whichloperatinglsystemlshouldlbelusedltolrunlthislcommand?

A.lWindows
B.lChrome
C.lBlackBerryl
D.lLinux


Answer:
D.lLinux




Q:lWhichlfilelsystemlislsupportedlbylMac?
A.lBerkeleylFastlFilelSysteml(FFS)
B.lExtendedlFilelSysteml(Ext)
C.lReiserlFilelSysteml(ReiserFS)
D.lHierarchicallFilelSystemlPlusl(HFS+)


Answer:
D.lHierarchicallFilelSystemlPlusl(HFS+)

, Q:lWherelarellocallpasswordslstoredlforlthelWindowsloperatinglsystem?
A.lSAMlfilelinl\Windows\System32\
B.lSAMlfilelinl\Windows\Security\
C.lInlthelregistrylkeylHKEY_LOCAL_MACHINE\SYSTEM
D.lInlthelregistrylkeylHKEY_LOCAL_MAHCINE\SECURITY


Answer:
A.lSAMlfilelinl\Windows\System32\




Q:lWherelonlalWindowslsystemlislthelconfiglfolderllocatedlthatlcontainslthelSAMlfile?
A.lC:\Windows\System32
B.lC:\Windows\SystemResources
C.lC:\ProgramlFiles
D.lC:\Users


Answer:
A.lC:\Windows\System32




Q:lWhatlshouldlalforensiclinvestigatorluseltolgatherlthelmostlreliablelroutinglinformationlforlt
rackinglanlemaillmessage?

A.lEmaillheader
B.lEmailladdress
C.lTracert
D.lNetstat


Answer:
A.lEmaillheader

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
nurse_steph Rasmussen College
View profile
Follow You need to be logged in order to follow users or courses
Sold
9395
Member since
5 year
Number of followers
5142
Documents
7587
Last sold
2 hours ago
Exams, Study guides, Reviews, Notes

All study solutions.

3.9

1682 reviews

5
846
4
297
3
259
2
78
1
202

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions