1 | Page
WGU MASTER'S COURSE C702 - FORENSICS
AND NETWORK INTRUSION 2025 UPDATED
ACTUAL EXAM WITH CORRECT SOLUTIONS.
A software company suspects that employees have set up
automatic corporate email forwarding to their personal inboxes
against company policy. The company hires forensic
investigators to identify the employees violating policy, with the
intention of issuing warnings to them.
Which type of cybercrime investigation approach is this
company taking?
A Civil
B Criminal
C Administrative
D Punitive - correct answer- C
Which model or legislation applies a holistic approach toward
any criminal activity as a criminal operation?
A Enterprise Theory of Investigation
B Racketeer Influenced and Corrupt Organizations Act
C Evidence Examination
,2 | Page
D Law Enforcement Cyber Incident Reporting - correct answer-
A
What does a forensic investigator need to obtain before seizing
a computing device in a criminal case?
A Court warrant
B Completed crime report
C Chain of custody document
D Plaintiff's permission - correct answer- A
Which activity should be used to check whether an application
has ever been installed on a computer?
A Penetration test
B Risk analysis
C Log review
D Security review - correct answer- C
Which characteristic describes an organization's forensic
readiness in the context of cybercrimes?
A It includes moral considerations.
,3 | Page
B It includes cost considerations.
C It excludes nontechnical actions.
D It excludes technical actions. - correct answer- B
A cybercrime investigator identifies a Universal Serial Bus
(USB) memory stick containing emails as a primary piece of
evidence.
Who must sign the chain of custody document once the USB
stick is in evidence?
A Those who obtain access to the device
B Anyone who has ever used the device
C Recipients of emails on the device
D Authors of emails on the device - correct answer- A
Which type of attack is a denial-of-service technique that sends
a large amount of data to overwhelm system resources?
A Phishing
B Spamming
C Mail bombing
D Bluejacking - correct answer- C
, 4 | Page
Which computer crime forensics step requires an investigator to
duplicate and image the collected digital information?
A Securing evidence
B Acquiring data
C Analyzing data
D Assessing evidence - correct answer- B
What is the last step of a criminal investigation that requires the
involvement of a computer forensic investigator?
A Analyzing the data collected
B Testifying in court
C Assessing the evidence
D Performing search and seizure - correct answer- B
How can a forensic investigator verify an Android mobile device
is on, without potentially changing the original evidence or
interacting with the operating system?
A Check to see if it is plugged into a computer
B Tap the screen multiple times
C Look for flashing lights
WGU MASTER'S COURSE C702 - FORENSICS
AND NETWORK INTRUSION 2025 UPDATED
ACTUAL EXAM WITH CORRECT SOLUTIONS.
A software company suspects that employees have set up
automatic corporate email forwarding to their personal inboxes
against company policy. The company hires forensic
investigators to identify the employees violating policy, with the
intention of issuing warnings to them.
Which type of cybercrime investigation approach is this
company taking?
A Civil
B Criminal
C Administrative
D Punitive - correct answer- C
Which model or legislation applies a holistic approach toward
any criminal activity as a criminal operation?
A Enterprise Theory of Investigation
B Racketeer Influenced and Corrupt Organizations Act
C Evidence Examination
,2 | Page
D Law Enforcement Cyber Incident Reporting - correct answer-
A
What does a forensic investigator need to obtain before seizing
a computing device in a criminal case?
A Court warrant
B Completed crime report
C Chain of custody document
D Plaintiff's permission - correct answer- A
Which activity should be used to check whether an application
has ever been installed on a computer?
A Penetration test
B Risk analysis
C Log review
D Security review - correct answer- C
Which characteristic describes an organization's forensic
readiness in the context of cybercrimes?
A It includes moral considerations.
,3 | Page
B It includes cost considerations.
C It excludes nontechnical actions.
D It excludes technical actions. - correct answer- B
A cybercrime investigator identifies a Universal Serial Bus
(USB) memory stick containing emails as a primary piece of
evidence.
Who must sign the chain of custody document once the USB
stick is in evidence?
A Those who obtain access to the device
B Anyone who has ever used the device
C Recipients of emails on the device
D Authors of emails on the device - correct answer- A
Which type of attack is a denial-of-service technique that sends
a large amount of data to overwhelm system resources?
A Phishing
B Spamming
C Mail bombing
D Bluejacking - correct answer- C
, 4 | Page
Which computer crime forensics step requires an investigator to
duplicate and image the collected digital information?
A Securing evidence
B Acquiring data
C Analyzing data
D Assessing evidence - correct answer- B
What is the last step of a criminal investigation that requires the
involvement of a computer forensic investigator?
A Analyzing the data collected
B Testifying in court
C Assessing the evidence
D Performing search and seizure - correct answer- B
How can a forensic investigator verify an Android mobile device
is on, without potentially changing the original evidence or
interacting with the operating system?
A Check to see if it is plugged into a computer
B Tap the screen multiple times
C Look for flashing lights