WGU C702 FORENSICS AND NETWORK INTRUSION EXAM
SCRIPT QUESTIONS AND ANSWERS RATED A+
✔✔RoadMASSter-3 X2 - ✔✔Ruggedized portable lab for HDD data acquisition and
analysis.
✔✔ZX-Tower - ✔✔Secure sanitization of hard disk
✔✔Data Recovery Stick - ✔✔Recovers deleted files
✔✔Tableau T8-R2 Forensic USB Bridge - ✔✔Write blocking of USB storage devices
✔✔Cain & Abel - ✔✔Password recovery for Windows OS
Sniffs the network, cracks encrypted passwords using dictionary, brute-force, and
cryptanalysis attacks
✔✔Recuva - ✔✔Recover lost pictures, music, docs, video, email. Recover all types of
lost files from disk or removable media
✔✔Capsa - ✔✔Sniffer
✔✔R-Drive Image - ✔✔Creation of disk image files for backup
✔✔FileMerlin - ✔✔Converts word processing to a wide range of file formats
✔✔AccessData FTK - ✔✔Court-cited digital investigations platform provides processing
and indexing up front
✔✔EnCase - ✔✔Rapidly acquire data and unearth potential evidence with disk-level
forensic analysis
✔✔The Sleuth Kit - ✔✔Command line tools to analyze disk images and recover files
✔✔L0phtCrack - ✔✔Password auditing and recovery software.
Recover lost Microsoft Windows passwords using a dictionary, hybrid, rainbow, and
brute-force attacks
✔✔Ophcrack - ✔✔Windows Password cracker based on rainbow tables
✔✔Computer Forensic Tool Testing Project (CFTT) - ✔✔NIST, establishes a
methodology for testing computer forensic software tools by development of general
tool specifications, test procedures, test criteria, test sets, and test hardware.
✔✔Image Integrity Tools - ✔✔HashCalc, MDF Calculator, HashMyFiles
,✔✔HashCalc - ✔✔Create MD5 has for files, text and hex string (13 different algorithms)
✔✔MDF Calculator - ✔✔View MD5 hash to compare to provided hash value
✔✔HashMyFiles - ✔✔Calculate MD5 hash on one or more files
File Fingerprinting
✔✔Recover My Files - ✔✔recover deleted files emptied from the windows recycle bin
and files lost due to the format or corruption of a hard drive, virus, or trojan infection,
and unexpected system shutdown or software failure
✔✔Advanced Disk Recovery - ✔✔Quick or deep scan for lost or deleted files
✔✔UndeletePlus - ✔✔Quick or deep scan for lost or deleted files. same as Advanced
Disk Recovery
✔✔Data Analysis Tools - ✔✔FTK Imager, EnCase Forensic, The Sleuth Kit (TSK)
✔✔FTK Imager - ✔✔imaging tools that enables analysis of files and folders on local
hard drives, CDs/DVDs, network drives and examination of the content of forensic
images or memory dumps
✔✔EnCase Forensic - ✔✔Generates and evidence report, acquire large amounts of
evidence, as fast as possible from laptops and desktop computers to mobile devices
✔✔The Sleuth Kit (TSK) - ✔✔Library and collection of command-line tools allowing
investigation of volume and file system data
fsstat
istat
fls
img_stat
✔✔Forensic Investigation Team - ✔✔Attorney, Photographer, Incident Responder,
Decision Maker, Incident Analyzer, Evidence, Examiner/Investigator, Evidence
Documenter, Evidence Manager, Expert Witness
✔✔18 USC 1029 - ✔✔Fraud and related activity in connection with access devices
✔✔18 USC 1030 - ✔✔Fraud and related activity in connection with computers
✔✔18 USC 1361-2 - ✔✔Prohibit malicious mischief
✔✔18 USC 2252A - ✔✔Child pornography
, ✔✔18 USC 2252B - ✔✔Misleading domains on Internet
✔✔18 USC 2702 - ✔✔Voluntary disclosure of customer communications or records
✔✔42 USC 2000AA - ✔✔Privacy Protection Act
✔✔Rule 402 - ✔✔Relevant Evidence
✔✔Rule 502 - ✔✔Attorney-Client Privilege and Work Product; Limitations on Waiver
✔✔Rule 608 - ✔✔Evidence of character and conduct of witness
✔✔Rule 609 - ✔✔Impeachment by evidence
✔✔Rule 614 - ✔✔Interrogation of Witnesses
✔✔Rule 701 - ✔✔Opinion testimony
✔✔Rule 705 - ✔✔Disclosure of facts
✔✔Platters - ✔✔Circular metal disks mounted into a drive enclosure
✔✔Tracks - ✔✔Concentric rings on the platters that store data
✔✔Track Numbering - ✔✔Starts at 0 and goes to 1023
✔✔Sectors - ✔✔Smallest physical storage unites located on a hard disk platter (512
bytes long)
✔✔Clusters - ✔✔Smallest accessible/logical storage unit on the hard disk
✔✔Slack Space - ✔✔Wasted are of the disk cluster lying between end of the file and
end of the cluster
✔✔Bad Sectors - ✔✔Portions of a disk that are unusable due to some flaws (Don't
support read and write)
✔✔Sparse File - ✔✔File that attempts to use file system space efficiently when
allocated blocks are mostly empty.
✔✔Cylinders, Head, and Sectors (CHS) - ✔✔Determine the sector addressing for
individual sectors on a disk
SCRIPT QUESTIONS AND ANSWERS RATED A+
✔✔RoadMASSter-3 X2 - ✔✔Ruggedized portable lab for HDD data acquisition and
analysis.
✔✔ZX-Tower - ✔✔Secure sanitization of hard disk
✔✔Data Recovery Stick - ✔✔Recovers deleted files
✔✔Tableau T8-R2 Forensic USB Bridge - ✔✔Write blocking of USB storage devices
✔✔Cain & Abel - ✔✔Password recovery for Windows OS
Sniffs the network, cracks encrypted passwords using dictionary, brute-force, and
cryptanalysis attacks
✔✔Recuva - ✔✔Recover lost pictures, music, docs, video, email. Recover all types of
lost files from disk or removable media
✔✔Capsa - ✔✔Sniffer
✔✔R-Drive Image - ✔✔Creation of disk image files for backup
✔✔FileMerlin - ✔✔Converts word processing to a wide range of file formats
✔✔AccessData FTK - ✔✔Court-cited digital investigations platform provides processing
and indexing up front
✔✔EnCase - ✔✔Rapidly acquire data and unearth potential evidence with disk-level
forensic analysis
✔✔The Sleuth Kit - ✔✔Command line tools to analyze disk images and recover files
✔✔L0phtCrack - ✔✔Password auditing and recovery software.
Recover lost Microsoft Windows passwords using a dictionary, hybrid, rainbow, and
brute-force attacks
✔✔Ophcrack - ✔✔Windows Password cracker based on rainbow tables
✔✔Computer Forensic Tool Testing Project (CFTT) - ✔✔NIST, establishes a
methodology for testing computer forensic software tools by development of general
tool specifications, test procedures, test criteria, test sets, and test hardware.
✔✔Image Integrity Tools - ✔✔HashCalc, MDF Calculator, HashMyFiles
,✔✔HashCalc - ✔✔Create MD5 has for files, text and hex string (13 different algorithms)
✔✔MDF Calculator - ✔✔View MD5 hash to compare to provided hash value
✔✔HashMyFiles - ✔✔Calculate MD5 hash on one or more files
File Fingerprinting
✔✔Recover My Files - ✔✔recover deleted files emptied from the windows recycle bin
and files lost due to the format or corruption of a hard drive, virus, or trojan infection,
and unexpected system shutdown or software failure
✔✔Advanced Disk Recovery - ✔✔Quick or deep scan for lost or deleted files
✔✔UndeletePlus - ✔✔Quick or deep scan for lost or deleted files. same as Advanced
Disk Recovery
✔✔Data Analysis Tools - ✔✔FTK Imager, EnCase Forensic, The Sleuth Kit (TSK)
✔✔FTK Imager - ✔✔imaging tools that enables analysis of files and folders on local
hard drives, CDs/DVDs, network drives and examination of the content of forensic
images or memory dumps
✔✔EnCase Forensic - ✔✔Generates and evidence report, acquire large amounts of
evidence, as fast as possible from laptops and desktop computers to mobile devices
✔✔The Sleuth Kit (TSK) - ✔✔Library and collection of command-line tools allowing
investigation of volume and file system data
fsstat
istat
fls
img_stat
✔✔Forensic Investigation Team - ✔✔Attorney, Photographer, Incident Responder,
Decision Maker, Incident Analyzer, Evidence, Examiner/Investigator, Evidence
Documenter, Evidence Manager, Expert Witness
✔✔18 USC 1029 - ✔✔Fraud and related activity in connection with access devices
✔✔18 USC 1030 - ✔✔Fraud and related activity in connection with computers
✔✔18 USC 1361-2 - ✔✔Prohibit malicious mischief
✔✔18 USC 2252A - ✔✔Child pornography
, ✔✔18 USC 2252B - ✔✔Misleading domains on Internet
✔✔18 USC 2702 - ✔✔Voluntary disclosure of customer communications or records
✔✔42 USC 2000AA - ✔✔Privacy Protection Act
✔✔Rule 402 - ✔✔Relevant Evidence
✔✔Rule 502 - ✔✔Attorney-Client Privilege and Work Product; Limitations on Waiver
✔✔Rule 608 - ✔✔Evidence of character and conduct of witness
✔✔Rule 609 - ✔✔Impeachment by evidence
✔✔Rule 614 - ✔✔Interrogation of Witnesses
✔✔Rule 701 - ✔✔Opinion testimony
✔✔Rule 705 - ✔✔Disclosure of facts
✔✔Platters - ✔✔Circular metal disks mounted into a drive enclosure
✔✔Tracks - ✔✔Concentric rings on the platters that store data
✔✔Track Numbering - ✔✔Starts at 0 and goes to 1023
✔✔Sectors - ✔✔Smallest physical storage unites located on a hard disk platter (512
bytes long)
✔✔Clusters - ✔✔Smallest accessible/logical storage unit on the hard disk
✔✔Slack Space - ✔✔Wasted are of the disk cluster lying between end of the file and
end of the cluster
✔✔Bad Sectors - ✔✔Portions of a disk that are unusable due to some flaws (Don't
support read and write)
✔✔Sparse File - ✔✔File that attempts to use file system space efficiently when
allocated blocks are mostly empty.
✔✔Cylinders, Head, and Sectors (CHS) - ✔✔Determine the sector addressing for
individual sectors on a disk