Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 3 fuera de 22 páginas
Examen

WGU D431 OA Exam 119 Questions with Verified Answers,100%CORRECT

Document preview thumbnail
Vista previa 3 fuera de 22 páginas

WGU D431 OA Exam 119 Questions with Verified Answers The process of acquiring and analyzing information stored on physical storage media, such as computer hard drives, smartphones, GPS systems, and removable media. Includes both the recovery of hidden and deleted information and the process of identifying who created a file or message. - CORRECT ANSWER Disk Forensics The study of the source and content of email as evidence, including the identification of the sender, recipient, date, time, and origination location of an email message. - CORRECT ANSWER Email Forensics the process of examining network traffic, including transaction logs and real-time monitoring using sniffers and tracing. - CORRECT ANSWER Network Forensics is the process of piecing together where and when a user has been on the internet. For example, you can use internet forensics to determine whether inappropriate internet content access and downloading were accidental. - CORRECT ANSWER Internet Forensics also known as malware forensics, is the process of examining malicious computer code - CORRECT ANSWER Software Forensics The process of searching memory in real time, typically for working with compromised hosts or to identify system abuse. - CORRECT ANSWER Live system forensics

Vista previa del contenido

WGU D431 OA Exam 119 Questions with Verified
Answers


The process of acquiring and analyzing information stored on physical storage
media, such as computer hard drives, smartphones, GPS systems, and removable
media. Includes both the recovery of hidden and deleted information and the
process of identifying who created a file or message. - CORRECT ANSWER Disk
Forensics


The study of the source and content of email as evidence, including the
identification of the sender, recipient, date, time, and origination location of an
email message. - CORRECT ANSWER Email Forensics


the process of examining network traffic, including transaction logs and real-time
monitoring using sniffers and tracing. - CORRECT ANSWER Network Forensics


is the process of piecing together where and when a user has been on the
internet. For example, you can use internet forensics to determine whether
inappropriate internet content access and downloading were accidental. -
CORRECT ANSWER Internet Forensics


also known as malware forensics, is the process of examining malicious computer
code - CORRECT ANSWER Software Forensics


The process of searching memory in real time, typically for working with
compromised hosts or to identify system abuse. - CORRECT ANSWER Live system
forensics

,is the process of searching the contents of cell phones. A few years ago, this was
just not a big issue, but with the ubiquitous nature of cell phones today, cell-
phone
forensics is a very important topic. A cell phone can be a treasure trove of
evidence. Modern
cell phones are essentially computers with processors, memory, even hard drives
and operating
systems, and they operate on networks. Phone forensics also includes VoIP and
traditional phones and may overlap the Foreign Intelligence Surveillance Act of
1978 (FISA), the USA
PATRIOT Act, and the Communications Assistance for Law Enforcement Act
(CALEA) in the United States. - CORRECT ANSWER Cell-Phone Forensics


From the time the evidence is first seized by a law
enforcement officer or civilian investigator until the moment it is shown in court,
the whereabouts and custody of the evidence, and how it was handled and stored
and by whom, must be able to be shown at all times. Failure to maintain the
proper chain of custody can lead to evidence being excluded from trial. - CORRECT
ANSWER Chain of Custody


One very important principle is to touch the system as little as possible. It is
possible to make changes to the system in the process of examining it, which is
very undesirable. Obviously, you have to interact with the system to investigate it.
The answer is to make a forensic copy and work with that copy. You can make a
forensic copy with most major forensic tools such as AccessData's Forensic Toolkit,
Guidance Software's EnCase, or PassMark's OSForensics. There are also open
source software products that allow copying of original source information. To be

, specific, make a copy and analyze the copy. - CORRECT ANSWER Don't Touch the
Suspect Drive


The next issue is documentation. The rule is that you document everything. Who
was present when the device was seized? What was connected to the device or
showing on the screen when you seized it? What specific tools and techniques did
you use? Who had access to the evidence from the time of seizure until the time
of trial? All of this must be documented. And when in doubt, err on the side of
over-documentation. It really is not possible to document too much information
about an investigation. - CORRECT ANSWER Document trail


It is absolutely critical to the integrity of your investigation as well as to
maintaining the chain of custody that you secure the evidence. It is common to
have the forensic lab be a locked room with access given only to those who must
enter. Then, evidence is usually secured in a safe, with access given out only on a
need-to-know basis. You have to take every reasonable precaution to ensure that
no one can tamper with the evidence. - CORRECT ANSWER Secure the Evidence


Standard used by a trial judge to make a preliminary assessment of whether an
expert's scientific testimony is based on reasoning or methodology that is
scientifically valid and can
properly be applied to the facts at issue. Under this standard, the factors that may
be considered in determining whether the methodology is valid are: (1) whether
the theory or
technique in question can be and has been tested; (2) whether it has been
subjected to peer
review and publication; (3) its known or potential error rate; (4) the existence and
maintenance

Información del documento

Subido en
24 de julio de 2025
Número de páginas
22
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$17.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
paulhans
3.5
(136)
Vendido
796
Seguidores
641
Artículos
7864
Última venta
2 semanas hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes