WGU C702 FINAL EXAM LATEST REAL EXAM QUESTIONS AND CORRECT VERIFIED
ANSWERS GRADED A+
A software company suspects that employees have set up automatic corporate email
forwarding to their personal inboxes against company policy. The company hires forensic
investigators to identify the employees violating policy, with the intention of issuing warnings to
them.
Which type of cybercrime investigation approach is this company taking?
Civil
Criminal
Administrative
Punitive - (ANSWER)Administrative !@#$%^&*()
Which model or legislation applies a holistic approach toward any criminal activity as a criminal
operation?
Enterprise Theory of Investigation
Racketeer Influenced and Corrupt Organizations Act
Evidence Examination
Law Enforcement Cyber Incident Reporting - (ANSWER)Enterprise Theory of Investigation
What does a forensic investigator need to obtain before seizing a computing device in a criminal
case?
Court warrant
Completed crime report
Chain of custody document
Plaintiff's permission - (ANSWER)Court warrant
Which activity should be used to check whether an application has ever been installed on a
computer?
Penetration test
Risk analysis
Log review
Security review - (ANSWER)Log review
Which characteristic describes an organization's forensic readiness in the context of
cybercrimes?
,WGU C702 FINAL EXAM LATEST REAL EXAM QUESTIONS AND CORRECT VERIFIED
ANSWERS GRADED A+
It includes moral considerations. It
includes cost considerations. It
excludes nontechnical actions.
It excludes technical actions. - (ANSWER)It includes cost considerations.
A cybercrime investigator identifies a Universal Serial Bus (USB) memory stick containing
emails as a primary piece of evidence.
Who must sign the chain of custody document once the USB stick is in evidence?
Those who obtain access to the device
Anyone who has ever used the device
Recipients of emails on the device
Authors of emails on the device - (ANSWER)Those who obtain access to the device
Which type of attack is a denial-of-service technique that sends a large amount of data to
overwhelm system resources?
Phishing
Spamming
Mail bombing
Bluejacking - (ANSWER)Mail bombing
Which computer crime forensics step requires an investigator to duplicate and image the
collected digital information?
Securing evidence
Acquiring data
Analyzing data
Assessing evidence - (ANSWER)Acquiring data
What is the last step of a criminal investigation that requires the involvement of a computer
forensic investigator?
Analyzing the data collected
Testifying in court
Assessing the evidence
, WGU C702 FINAL EXAM LATEST REAL EXAM QUESTIONS AND CORRECT VERIFIED
ANSWERS GRADED A+
Performing search and seizure - (ANSWER)Testifying in court
How can a forensic investigator verify an Android mobile device is on, without potentially
changing the original evidence or interacting with the operating system?
Check to see if it is plugged into a computer Tap
the screen multiple times
Look for flashing lights
Hold down the power button - (ANSWER)Look for flashing lights
What should a forensic investigator use to protect a mobile device if a Faraday bag is not
available?
Aluminum foil
Sturdy container
Cardboard box
Bubble wrap - (ANSWER)Aluminum foil
Which criterion determines whether a technology used by government to obtain
information in a computer search is considered innovative and requires a search warrant?
Availability to the general public
Dependency on third-party software Implementation
based on open source software
Use of cloud-based machine learning - (ANSWER)Availability to the general public
Which situation allows a law enforcement officer to seize a hard drive from a residence without
obtaining a search warrant?
The computer is left unattended.
The front door is wide open.
The occupant is acting suspicious.
The evidence is in imminent danger. - (ANSWER)The evidence is in imminent danger.
Which legal document contains a summary of findings and is used to prosecute?
Investigation report
Search warrant
ANSWERS GRADED A+
A software company suspects that employees have set up automatic corporate email
forwarding to their personal inboxes against company policy. The company hires forensic
investigators to identify the employees violating policy, with the intention of issuing warnings to
them.
Which type of cybercrime investigation approach is this company taking?
Civil
Criminal
Administrative
Punitive - (ANSWER)Administrative !@#$%^&*()
Which model or legislation applies a holistic approach toward any criminal activity as a criminal
operation?
Enterprise Theory of Investigation
Racketeer Influenced and Corrupt Organizations Act
Evidence Examination
Law Enforcement Cyber Incident Reporting - (ANSWER)Enterprise Theory of Investigation
What does a forensic investigator need to obtain before seizing a computing device in a criminal
case?
Court warrant
Completed crime report
Chain of custody document
Plaintiff's permission - (ANSWER)Court warrant
Which activity should be used to check whether an application has ever been installed on a
computer?
Penetration test
Risk analysis
Log review
Security review - (ANSWER)Log review
Which characteristic describes an organization's forensic readiness in the context of
cybercrimes?
,WGU C702 FINAL EXAM LATEST REAL EXAM QUESTIONS AND CORRECT VERIFIED
ANSWERS GRADED A+
It includes moral considerations. It
includes cost considerations. It
excludes nontechnical actions.
It excludes technical actions. - (ANSWER)It includes cost considerations.
A cybercrime investigator identifies a Universal Serial Bus (USB) memory stick containing
emails as a primary piece of evidence.
Who must sign the chain of custody document once the USB stick is in evidence?
Those who obtain access to the device
Anyone who has ever used the device
Recipients of emails on the device
Authors of emails on the device - (ANSWER)Those who obtain access to the device
Which type of attack is a denial-of-service technique that sends a large amount of data to
overwhelm system resources?
Phishing
Spamming
Mail bombing
Bluejacking - (ANSWER)Mail bombing
Which computer crime forensics step requires an investigator to duplicate and image the
collected digital information?
Securing evidence
Acquiring data
Analyzing data
Assessing evidence - (ANSWER)Acquiring data
What is the last step of a criminal investigation that requires the involvement of a computer
forensic investigator?
Analyzing the data collected
Testifying in court
Assessing the evidence
, WGU C702 FINAL EXAM LATEST REAL EXAM QUESTIONS AND CORRECT VERIFIED
ANSWERS GRADED A+
Performing search and seizure - (ANSWER)Testifying in court
How can a forensic investigator verify an Android mobile device is on, without potentially
changing the original evidence or interacting with the operating system?
Check to see if it is plugged into a computer Tap
the screen multiple times
Look for flashing lights
Hold down the power button - (ANSWER)Look for flashing lights
What should a forensic investigator use to protect a mobile device if a Faraday bag is not
available?
Aluminum foil
Sturdy container
Cardboard box
Bubble wrap - (ANSWER)Aluminum foil
Which criterion determines whether a technology used by government to obtain
information in a computer search is considered innovative and requires a search warrant?
Availability to the general public
Dependency on third-party software Implementation
based on open source software
Use of cloud-based machine learning - (ANSWER)Availability to the general public
Which situation allows a law enforcement officer to seize a hard drive from a residence without
obtaining a search warrant?
The computer is left unattended.
The front door is wide open.
The occupant is acting suspicious.
The evidence is in imminent danger. - (ANSWER)The evidence is in imminent danger.
Which legal document contains a summary of findings and is used to prosecute?
Investigation report
Search warrant