1|Page
WGU C702 OBJECTIVE ASSESSMENT EXAM AND PRACTICE EXAM
NEWEST 2025 ACTUAL EXAM WITH COMPLETE EXAM QUESTIONS
AND CORRECT DETAILED ANSWERS (100% VERIFIED ANSWERS)
|ALREADY GRADED A+| ||PROFESSOR VERIFIED||
A forensic investigator receives dozens of log-in failure events
within a few minutes. A security attack event is generated. What
is the goal when performing event correlation? - ANSWER-Root
cause identification
A computer forensic investigator is preparing an affidavit
statement. Which type of report should this investigator prepare? -
ANSWER-Formal written
A forensic investigator is preparing a report in response to a
security breach. The report is augmented by documentation
provided by a third party. Which optional section in the report
serves as a gesture of thanks for the third-party support? -
ANSWER-Acknowledgments
A network log from a remote system is entered into evidence, and
the proper steps are taken to protect the integrity of the data. The
log contains network intrusion data but does not contain any
,2|Page
information about the log.What must an investigator document
about this log in the forensic report? - ANSWER-Name of the
server
What should an investigator do to ensure that creating a forensic
hard drive image does not alter the drive? - ANSWER-Make a
duplicate using the dd command
A Mac computer that does not have removeable batteries is
powered on. Which action must a first responder take to preserve
digital evidence from the computer once volatile information is
collected? - ANSWER-Press the power switch for 30 seconds
What should an investigator do to ensure that a phone serving as
evidence at a crime scene is properly isolated? - ANSWER-Use a
Faraday bag
First responders arrive at a company and determine that a non-
company Windows 7 computer was used to breach information
systems. The computer is still powered on. What is the correct
procedure for powering off this computer once the volatile
, 3|Page
information has been collected? - ANSWER-Unplug the electrical
cord from the wall socket
What is the minimum number of workstations a forensics lab
needs? - ANSWER-Two
Which function does the BIOS parameter block (BPB) handle for
the hard disk? - ANSWER-Describes the physical layout and
volume partitions
How does RAID 3 store information? - ANSWER-Information is
written at byte level across multiple drives, but only one is
dedicated for parity.
Which file system is on a system with MacOS installed? -
ANSWER-Hierarchical File System Plus (HFS+)
Where should an investigator search for details of activities that
have taken place in an SQL database? - ANSWER-Transaction
log data files (LDF)
WGU C702 OBJECTIVE ASSESSMENT EXAM AND PRACTICE EXAM
NEWEST 2025 ACTUAL EXAM WITH COMPLETE EXAM QUESTIONS
AND CORRECT DETAILED ANSWERS (100% VERIFIED ANSWERS)
|ALREADY GRADED A+| ||PROFESSOR VERIFIED||
A forensic investigator receives dozens of log-in failure events
within a few minutes. A security attack event is generated. What
is the goal when performing event correlation? - ANSWER-Root
cause identification
A computer forensic investigator is preparing an affidavit
statement. Which type of report should this investigator prepare? -
ANSWER-Formal written
A forensic investigator is preparing a report in response to a
security breach. The report is augmented by documentation
provided by a third party. Which optional section in the report
serves as a gesture of thanks for the third-party support? -
ANSWER-Acknowledgments
A network log from a remote system is entered into evidence, and
the proper steps are taken to protect the integrity of the data. The
log contains network intrusion data but does not contain any
,2|Page
information about the log.What must an investigator document
about this log in the forensic report? - ANSWER-Name of the
server
What should an investigator do to ensure that creating a forensic
hard drive image does not alter the drive? - ANSWER-Make a
duplicate using the dd command
A Mac computer that does not have removeable batteries is
powered on. Which action must a first responder take to preserve
digital evidence from the computer once volatile information is
collected? - ANSWER-Press the power switch for 30 seconds
What should an investigator do to ensure that a phone serving as
evidence at a crime scene is properly isolated? - ANSWER-Use a
Faraday bag
First responders arrive at a company and determine that a non-
company Windows 7 computer was used to breach information
systems. The computer is still powered on. What is the correct
procedure for powering off this computer once the volatile
, 3|Page
information has been collected? - ANSWER-Unplug the electrical
cord from the wall socket
What is the minimum number of workstations a forensics lab
needs? - ANSWER-Two
Which function does the BIOS parameter block (BPB) handle for
the hard disk? - ANSWER-Describes the physical layout and
volume partitions
How does RAID 3 store information? - ANSWER-Information is
written at byte level across multiple drives, but only one is
dedicated for parity.
Which file system is on a system with MacOS installed? -
ANSWER-Hierarchical File System Plus (HFS+)
Where should an investigator search for details of activities that
have taken place in an SQL database? - ANSWER-Transaction
log data files (LDF)