Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

WGU MASTER'S COURSE C702 - FORENSICS AND NETWORK INTRUSION 475 COMPLETE QUESTIONS AND 100% CORRECT ANSWERS NEW UPDATE ASSURED PASS!!!!!!!!!!!!!!!

Beoordeling
-
Verkocht
-
Pagina's
98
Cijfer
A+
Geüpload op
19-05-2026
Geschreven in
2025/2026

This comprehensive WGU Master study guide features actual exam questions with correct answers covering digital forensics and cyber investigation—designed for WGU students and cybersecurity professionals. Covering all core domains including forensic tools (SAFE Block—software write blocker for storage devices, ApexSQL DBA for database changes, SmartWhois for public IP information, Chat Stick for messaging logs, Andriller for mobile database acquisition, EnCase for Windows forensic imaging, ProDiscover for evidence location and reporting, Wireshark for TCP stream analysis), evidence handling (chain of custody requires signatures from everyone who accesses device, first responder responsibilities—document, preserve, leave devices as found, package evidence; Faraday bag for mobile device isolation, aluminum foil alternative, live data acquisition from powered-on devices—collect with secure command shell, hardware write blocker for forensic laptop connection, bit-stream copy using dd command for disk-to-disk acquisition), legal and ethical (court warrant required before seizing device in criminal case, Fourth Amendment compliance for search and seizure, imminent danger exception to warrant requirement, expert witness role—educate court and public, civil vs criminal vs administrative cybercrime investigations, Enterprise Theory of Investigation holistic approach to criminal operations), operating system forensics (Windows—SAM database for user information, $Recycle.Bin for deleted items Windows Vista+, INFO2 file for Recycle Bin records, Event Viewer, Wevtutil for Windows 10 event logs, prefetch EnablePrefetcher values 0-3, PSLoggedon for remote users, net sessions for username and IP; Linux—/var/log/ system logs, dmesg for kernel ring buffer, ausearch for user events, fsstat, istat, fls The Sleuth Kit commands, ext3 maximum 32 TB; macOS—PLIST files, /var/log/, DaveGrohl password cracker, HFS+ file system, logical block 2 for Master Directory Block, logical block 3 for volume bitmap start; mobile forensics—Android based on Linux, Andriller for data acquisition, iOS jailbreaking tool Redsn0w, verify device on by looking for flashing lights without touching), file systems and storage (FAT32 maximum file size 4 GB, NTFS Master File Table as relational database, cluster size smaller than FAT reduces slack space, Ext2 superblock with magic number, Ext3 journaling file system, HFS allocation block limit 65,535, GPT advantage over MBR—supports disks larger than 2 TB, LBA 1 for GPT header, LBA 34 first usable sector, RAID 0 striping no redundancy, RAID 1 mirroring, RAID 5 byte-level striping with distributed parity, RAID 10 combination striping and mirroring), malware and anti-forensics (rootkit detection, obfuscator to avoid detection, signature-based detection compares fingerprints, steganography—folder steganography keeps associated files in original location, image steganography embedding text in PNG file), network forensics (NIC promiscuous mode at OSI Physical layer, DDoS attacks from botnets, wireless AP MAC spoofing, wireless jamming signal attack), web application attacks (buffer overflow corrupts execution stack, cookie poisoning, SQL injection, cross-site scripting, cross-site request forgery, directory traversal, unvalidated input, parameter tampering, denial of service, broken access control), email forensics (Microsoft Exchange .EDB files, PRIV.STM for MIME stream content, RFC 5322 defines normal email communication, Errors-To header for bounce messages, email header required for investigation, X-Distribution header for multiple recipients), cloud forensics (IaaS, PaaS, SaaS, private cloud expense as disadvantage, public cloud available over internet, community cloud shared among organizations, hybrid cloud combines multiple models, NIST CFTTP for testing forensic tools), and professional practice (codes of ethics—no personal opinions, testify as expert witness, DACUM process for job analysis). Ideal for WGU digital forensics courses, cybersecurity certifications, and computer investigation exam preparation.

Meer zien Lees minder
Instelling
WGU Master: Digital
Vak
WGU Master: Digital

Voorbeeld van de inhoud

WGU MASTER'S COURSE C702 - FORENSICS AND NETWORK
INTRUSION 475 COMPLETE QUESTIONS AND 100% CORRECT
ANSWERS NEW UPDATE ASSURED PASS!!!!!!!!!!!!!!!




Which software-based tool is used to prevent writes to storage devices on a
computer?

A CRU WiebeTech
B ILook Investigator
C SAFE Block
D USB WriteBlocker - ANS... -C

Which tool should a forensic team use to research unauthorized changes in a
database?

A ApexSQL DBA
B Gargoyle Investigator Forensic Pro
C LSASecretsView
D RSA NetWitness Investigator - ANS... -A

Which graphical tool should investigators use to identify publicly available
information about a public IP address?

A AWStats
B GoAccess
C SmartWhois
D NsLookup - ANS... -C

Which tool is used to search and analyze PC messaging logs?

A Chat Stick
B File Viewer
C SnowBatch
D Zamzar - ANS... -A

,Which forensic tool allows an investigator to acquire database files for analysis
from a mobile device?

A Andriller
B Volatility
C WinDump
D Tripwire - ANS... -A

A first responder arrives at an active crime scene that has several mobile devices.

What should this first responder do while securing the crime scene?

A Leave the devices in the state they are in and put them in anti-static bags
B Turn on the devices and review recently accessed data
C Turn off the devices to preserve the volatile memory
D Leave the devices as found and fill out chain of custody paperwork - ANS... -D

What is a responsibility of the first responder at a crime scene?

A Package and transport the evidence
B Identify the presence of rootkits on the evidence
C Decrypt the evidence by cracking passwords
D Detect malware present on the evidence - ANS... -A

Which step preserves the forensic integrity of volatile evidence when a device is
discovered in the powered-on state?

A Documenting the procedures for shutting down the system
B Collecting information with a secure command shell
C Using the built-in backup utility to gather information
D Copying the file with the keyboard shortcut Ctrl+C - ANS... -B

Which action maintains the integrity of evidence when a forensic laptop is used to
acquire data from a compromised computer?

A Connecting the machines with a straight through cable
B Connecting the machines with a crossover cable
C Enabling a hardware write blocker
D Enabling administrative control - ANS... -C

,What should an investigator do while collecting evidence from a device?

A Turn off the computer to protect the data
B Install antivirus software to protect information
C Begin documenting the chain of custody
D Close any open documents and applications - ANS... -C

A software company suspects that employees have set up automatic corporate
email forwarding to their personal inboxes against company policy. The company
hires forensic investigators to identify the employees violating policy, with the
intention of issuing warnings to them.

Which type of cybercrime investigation approach is this company taking?

A Civil
B Criminal
C Administrative
D Punitive - ANS... -C

Which model or legislation applies a holistic approach toward any criminal activity
as a criminal operation?

A Enterprise Theory of Investigation
B Racketeer Influenced and Corrupt Organizations Act
C Evidence Examination
D Law Enforcement Cyber Incident Reporting - ANS... -A

What does a forensic investigator need to obtain before seizing a computing device
in a criminal case?

A Court warrant
B Completed crime report
C Chain of custody document
D Plaintiff's permission - ANS... -A

Which activity should be used to check whether an application has ever been
installed on a computer?

A Penetration test
B Risk analysis

, C Log review
D Security review - ANS... -C

Which characteristic describes an organization's forensic readiness in the context
of cybercrimes?

A It includes moral considerations.
B It includes cost considerations.
C It excludes nontechnical actions.
D It excludes technical actions. - ANS... -B

A cybercrime investigator identifies a Universal Serial Bus (USB) memory stick
containing emails as a primary piece of evidence.

Who must sign the chain of custody document once the USB stick is in evidence?

A Those who obtain access to the device
B Anyone who has ever used the device
C Recipients of emails on the device
D Authors of emails on the device - ANS... -A

Which type of attack is a denial-of-service technique that sends a large amount of
data to overwhelm system resources?

A Phishing
B Spamming
C Mail bombing
D Bluejacking - ANS... -C

Which computer crime forensics step requires an investigator to duplicate and
image the collected digital information?

A Securing evidence
B Acquiring data
C Analyzing data
D Assessing evidence - ANS... -B

What is the last step of a criminal investigation that requires the involvement of a
computer forensic investigator?

Geschreven voor

Instelling
WGU Master: Digital
Vak
WGU Master: Digital

Documentinformatie

Geüpload op
19 mei 2026
Aantal pagina's
98
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

€18,58
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper
Seller avatar
PrepPulse

Maak kennis met de verkoper

Seller avatar
PrepPulse NURSING, ECONOMICS, MATHEMATICS, BIOLOGY, AND HISTORY MATERIALS BEST TUTORING, HOMEWORK HELP, EXAMS, TESTS, AND STUDY GUIDE MATERIALS WITH GUARANTEED A+ I am a dedicated medical practitioner with diverse knowledge in matters
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
-
Lid sinds
1 week
Aantal volgers
0
Documenten
152
Laatst verkocht
-
ExamSmart

Exams feel overwhelming, but the right notes change everything. Here you'll find easy-to-follow summaries, step-by-step solutions, and practice materials that turn tough topics into manageable pieces. I create everything to match your actual exam board and keep it updated so you're never studying the wrong thing. Let's make your next exam your best one.

0,0

0 beoordelingen

5
0
4
0
3
0
2
0
1
0

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen