WGU D431 OA EXAM, MOST RECENT EXAM 2026
ACTUAL COMPLETE REAL VERIFIED EXAM
QUESTIONS AND CORRECT ANSWERS (VERIFIED
ANSWERS) ALREADY GRADED A+ || NEWEST
EXAM!!!
In a computer forensics investigation, this describes the
route that evidence takes from the time you find it until the
case is closed or goes to court. - Answer-Chain of custody
If the computer is turned on when you arrive, what does
the Secret Service recommend you do? - Answer-Shut the
computer down according to the recommended Secret
Service procedure.
Why should you note all cable connections for a computer
you want to seize as evidence? - Answer-In case other
devices were connected
What is the essence of the Daubert standard? - Answer-
That only tools or techniques that have been accepted by
the scientific community are admissible at trial
,2|Page
When cataloging digital evidence, the primary goal is to do
what? - Answer-Preserve evidence integrity.
Which of the following is important to the investigator
regarding logging? - Answer-All of the above
Your roommate can give consent to search your computer.
- Answer-False
Evidence need not be locked if it is at a police station. -
Answer-False
When investigating a virus, what is the first step? -
Answer-Document the virus.
Which of the following crimes is most likely to leave email
evidence? - Answer-Cyberstalking
Where would you seek evidence that Ophcrack had been
used on a Windows Server 2008 machine? - Answer-In
the logs of the server; look for the reboot of the system
, 3|Page
Logic bombs are often perpetrated by _________. -
Answer-Disgruntled employees
Spyware is legal. - Answer-True
It is legal for employers to monitor work computers. -
Answer-True
What is the primary reason to take cyberstalking
seriously? - Answer-It can be a prelude to real-world
violence.
What is the starting point for investigating denial-of-service
attacks? - Answer-Tracing the packets
To preserve digital evidence, an investigator should
______. - Answer-Make two copies of each evidence item
using different imaging tools
Bob was asked to make a copy of all the evidence from
the compromised system. Melanie did a DOS copy of all
the files on the system. What would be the primary reason
for you to recommend for or against using a disk-imaging