Course C702 -
Forensics and
Network
Intrusion
, WGU Master's Course C702 - Forensics and Network
Intrusion With Complete Solution
A software company suspects that employees have set up automatic corporate email
forwarding to their personal inboxes against company policy. The company hires
forensic investigators to identify the employees violating policy, with the intention of
issuing warnings to them.
Which type of cybercrime investigation approach is this company taking?
A Civil
B Criminal
C Administrative
D Punitive -CORRECT ANSWER C
Which model or legislation applies a holistic approach toward any criminal activity as a
criminal operation?
A Enterprise Theory of Investigation
B Racketeer Influenced and Corrupt Organizations Act
C Evidence Examination
D Law Enforcement Cyber Incident Reporting -CORRECT ANSWER A
What does a forensic investigator need to obtain before seizing a computing device in a
criminal case?
A Court warrant
B Completed crime report
C Chain of custody document
D Plaintiff's permission -CORRECT ANSWER A
Which activity should be used to check whether an application has ever been installed
on a computer?
A Penetration test
B Risk analysis
C Log review
D Security review -CORRECT ANSWER C
Which characteristic describes an organization's forensic readiness in the context of
cybercrimes?
A It includes moral considerations.
B It includes cost considerations.
C It excludes nontechnical actions.
, WGU Master's Course C702 - Forensics and Network
Intrusion With Complete Solution
D It excludes technical actions. -CORRECT ANSWER B
A cybercrime investigator identifies a Universal Serial Bus (USB) memory stick
containing emails as a primary piece of evidence.
Who must sign the chain of custody document once the USB stick is in evidence?
A Those who obtain access to the device
B Anyone who has ever used the device
C Recipients of emails on the device
D Authors of emails on the device -CORRECT ANSWER A
Which type of attack is a denial-of-service technique that sends a large amount of data
to overwhelm system resources?
A Phishing
B Spamming
C Mail bombing
D Bluejacking -CORRECT ANSWER C
Which computer crime forensics step requires an investigator to duplicate and image
the collected digital information?
A Securing evidence
B Acquiring data
C Analyzing data
D Assessing evidence -CORRECT ANSWER B
What is the last step of a criminal investigation that requires the involvement of a
computer forensic investigator?
A Analyzing the data collected
B Testifying in court
C Assessing the evidence
D Performing search and seizure -CORRECT ANSWER B
How can a forensic investigator verify an Android mobile device is on, without potentially
changing the original evidence or interacting with the operating system?
A Check to see if it is plugged into a computer
B Tap the screen multiple times
C Look for flashing lights
D Hold down the power button -CORRECT ANSWER C
, WGU Master's Course C702 - Forensics and Network
Intrusion With Complete Solution
What lshould la lforensic linvestigator luse lto lprotect la lmobile ldevice lif la lFaraday lbag lis lnot
lavailable?
A lAluminum lfoil
B lSturdy lcontainer
C lCardboard lbox
D lBubble lwrap l-CORRECT lANSWER A
Which lcriterion ldetermines lwhether la ltechnology lused lby lgovernment lto lobtain
linformation lin la lcomputer lsearch lis lconsidered linnovative land lrequires la lsearch
lwarrant?
A lAvailability lto lthe lgeneral lpublic
B lDependency lon lthird-party lsoftware
C lImplementation lbased lon lopen lsource lsoftware
D lUse lof lcloud-based lmachine llearning l-CORRECT lANSWER A
Which lsituation lallows la llaw lenforcement lofficer lto lseize la lhard ldrive lfrom la lresidence
lwithout lobtaining la lsearch lwarrant?
A lThe lcomputer lis lleft lunattended.
B lThe lfront ldoor lis lwide lopen.
C lThe loccupant lis lacting lsuspicious.
D lThe levidence lis lin limminent ldanger. l-CORRECT lANSWER D
Which llegal ldocument lcontains la lsummary lof lfindings land lis lused lto lprosecute?
A lInvestigation lreport
B lSearch lwarrant
C lSearch land lseizure
D lChain lof lcustody l-CORRECT lANSWER A
What lshould lan linvestigator luse lto lprevent lany lsignals lfrom lreaching la lmobile lphone?
A lFaraday lbag
B lDry lbag
C lAnti-static lcontainer
D lLock lbox l-CORRECT lANSWER A
A lforensic linvestigator lis lcalled lto lthe lstand las la ltechnical lwitness lin lan linternet lpayment
lfraud lcase.
Which lbehavior lis lconsidered lethical lby lthis linvestigator lwhile ltestifying?
A lProviding land lexplaining lfacts lfound lduring lthe linvestigation