WGU C702 – Forensics and Network Intrusion OA
WGU C702 – Forensics and Network
Intrusion OA Practice Exam Questions
and Answers 2026. Advanced NCLEX-
Style 100 MCQs with Rationales
Q1
A forensic investigator arrives at a crime scene involving a compromised server. What should be
collected FIRST?
A. Hard drive image
B. Volatile memory contents
C. System logs
D. User accounts
Answer: B
Rationale: Volatile data (RAM, active connections, running processes) disappears when power
is removed. It should be captured before nonvolatile evidence.
Q2
Which hashing algorithm is considered the strongest among the following for forensic integrity
verification?
A. MD5
B. SHA-1
C. SHA-256
D. CRC32
Answer: C
Rationale: SHA-256 provides significantly stronger collision resistance than MD5 and SHA-1.
, WGU C702 – Forensics and Network Intrusion OA
Q3
Which document tracks every person who handled evidence?
A. Incident Report
B. Audit Log
C. Chain of Custody Form
D. Evidence Manifest
Answer: C
Rationale: Chain of custody ensures evidence accountability and admissibility in court.
Q4
A write blocker is used primarily to:
A. Encrypt evidence
B. Compress evidence
C. Prevent modification of evidence
D. Destroy malware
Answer: C
Rationale: Write blockers prevent accidental changes to original storage media during
acquisition.
Q5
Which investigation type examines employee violations of company policy?
A. Criminal
B. Civil
C. Administrative
D. Regulatory
Answer: C
Rationale: Administrative investigations address internal policy violations.
, WGU C702 – Forensics and Network Intrusion OA
Q6
Which forensic image format supports metadata and compression?
A. RAW (dd)
B. E01
C. ISO
D. FAT32
Answer: B
Rationale: Expert Witness Format (E01) supports compression, metadata, and integrity checks.
Q7
What is the primary purpose of network forensics?
A. Recover deleted files
B. Analyze network traffic for evidence
C. Repair damaged systems
D. Encrypt communications
Answer: B
Rationale: Network forensics reconstructs events using captured traffic and logs.
Q8
Which TCP flag combination is commonly associated with an XMAS scan?
A. SYN
B. FIN
C. FIN, PSH, URG
D. ACK
Answer: C
Rationale: XMAS scans set FIN, PSH, and URG flags simultaneously.
Q9
, WGU C702 – Forensics and Network Intrusion OA
A forensic examiner discovers evidence of unauthorized access to a database. Which log source
is MOST valuable?
A. Printer logs
B. Database transaction logs
C. DHCP logs
D. BIOS logs
Answer: B
Rationale: Database logs provide direct evidence of queries and modifications.
Q10
Which file system is most commonly associated with modern Windows systems?
A. ext4
B. HFS+
C. NTFS
D. UFS
Answer: C
Rationale: NTFS is the default file system for current Windows installations.
Q11
What is steganography?
A. Data encryption
B. Data destruction
C. Hiding information inside another file
D. Hashing evidence
Answer: C
Rationale: Steganography conceals information within images, audio, or other media.
Q12
WGU C702 – Forensics and Network
Intrusion OA Practice Exam Questions
and Answers 2026. Advanced NCLEX-
Style 100 MCQs with Rationales
Q1
A forensic investigator arrives at a crime scene involving a compromised server. What should be
collected FIRST?
A. Hard drive image
B. Volatile memory contents
C. System logs
D. User accounts
Answer: B
Rationale: Volatile data (RAM, active connections, running processes) disappears when power
is removed. It should be captured before nonvolatile evidence.
Q2
Which hashing algorithm is considered the strongest among the following for forensic integrity
verification?
A. MD5
B. SHA-1
C. SHA-256
D. CRC32
Answer: C
Rationale: SHA-256 provides significantly stronger collision resistance than MD5 and SHA-1.
, WGU C702 – Forensics and Network Intrusion OA
Q3
Which document tracks every person who handled evidence?
A. Incident Report
B. Audit Log
C. Chain of Custody Form
D. Evidence Manifest
Answer: C
Rationale: Chain of custody ensures evidence accountability and admissibility in court.
Q4
A write blocker is used primarily to:
A. Encrypt evidence
B. Compress evidence
C. Prevent modification of evidence
D. Destroy malware
Answer: C
Rationale: Write blockers prevent accidental changes to original storage media during
acquisition.
Q5
Which investigation type examines employee violations of company policy?
A. Criminal
B. Civil
C. Administrative
D. Regulatory
Answer: C
Rationale: Administrative investigations address internal policy violations.
, WGU C702 – Forensics and Network Intrusion OA
Q6
Which forensic image format supports metadata and compression?
A. RAW (dd)
B. E01
C. ISO
D. FAT32
Answer: B
Rationale: Expert Witness Format (E01) supports compression, metadata, and integrity checks.
Q7
What is the primary purpose of network forensics?
A. Recover deleted files
B. Analyze network traffic for evidence
C. Repair damaged systems
D. Encrypt communications
Answer: B
Rationale: Network forensics reconstructs events using captured traffic and logs.
Q8
Which TCP flag combination is commonly associated with an XMAS scan?
A. SYN
B. FIN
C. FIN, PSH, URG
D. ACK
Answer: C
Rationale: XMAS scans set FIN, PSH, and URG flags simultaneously.
Q9
, WGU C702 – Forensics and Network Intrusion OA
A forensic examiner discovers evidence of unauthorized access to a database. Which log source
is MOST valuable?
A. Printer logs
B. Database transaction logs
C. DHCP logs
D. BIOS logs
Answer: B
Rationale: Database logs provide direct evidence of queries and modifications.
Q10
Which file system is most commonly associated with modern Windows systems?
A. ext4
B. HFS+
C. NTFS
D. UFS
Answer: C
Rationale: NTFS is the default file system for current Windows installations.
Q11
What is steganography?
A. Data encryption
B. Data destruction
C. Hiding information inside another file
D. Hashing evidence
Answer: C
Rationale: Steganography conceals information within images, audio, or other media.
Q12