WGU C702 - Forensics and Network Intrusion Exam 2022

WGU EXAMS Sep 5, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

  • /
  • WGU C702 - Forensics and Network Intrusion Exam 2022 1.Which documentation should a forensic examiner prepare prior to a dy- namic analysis (answer) The full path and location of the file being investigated 2.What allows for a lawful search to be conducted without a warrant or probable cause (answer) Consent of person with authority 3.A forensic investigator is tasked with retrieving evidence where the prima- ry server has been erased. The investigator needs to rely on network logs and backup tapes to base their conclusions on while testifying in court. Which information found in rules of evidence, Rule 1001, helps determine if this testimony is acceptable to the court (answer) Definition of original evidence 4.When can a forensic investigator collect evidence without formal con- sent (answer) When properly worded banners are displayed on the computer screen 5.Who determines whether a forensic investigation should take place if a situation is undocumented in the standard operating procedures (answer) Decision maker 6.Which situation leads to a civil investigation (answer) Disputes between two parties that relate to a contract violation 7.Which rule does a forensic investigator need to follow (answer) Use well-known standard procedures 1 / 3

  • /
  • 8.What is the focus of Locard's exchange principle (answer) Anyone entering a crime scene takes something with them and leaves something behind.

    9.What is the focus of the enterprise theory of investigation (ETI) (answer) Solving one crime can tie it back to a criminal organization's activities.

    10.A forensic investigator is searching a Windows XP computer image for information about a deleted Word document. The investigator already viewed the sixth file that was deleted from the computer. Two additional files were deleted. What is the name of the last file the investigator opens (answer) $R7.doc 11.What is a benefit of a web application firewall (WAF) (answer) Acts as a reverse proxy to inspect all HTTP traffic 12.How does a hacker bypass a web application firewall (WAF) with the toggle case technique (answer) By randomly capitalizing some of the characters 13.During a recent scan of a network, a network administrator sent ICMP echo 8 packets to each IP address being used in the network. The ICMP echo 8 packets contained an invalid media access control (MAC) address.Logs showed that one device replied with ICMP echo 0 packets. What does the reply from the single device indicate (answer) The machine is in promiscuous mode. 2 / 3

  • /
  • 14.What is the goal for an attacker using a directory traversal attack (answer) To access areas in the system in which the attacker should not have access 15.A forensic investigator is performing malware analysis on a Windows computer. The investigator believes malware has replaced the legitimate drivers with fake versions. What should the investigator look at to confirm these suspicions (answer) The digital signatures on the drivers 16.Where should an investigator look in the registry to find artifacts if there is malware on a Windows system (answer) HKLM\SOFTWARE\ Microsoft\Win- dows\CurrentVersion\Run 17.Company A is using Company B to host data. Company A lets Company B perform all the daily activities of managing the data. Company A's customers are unaware of the security procedures Company B uses to host the data. Which threat does this depict (answer) Unknown risk profile 18.Which type of information can a forensic investigator find in a common metadata field for a file (answer) Network name 19.A forensic investigator is tasked with finding out if a suspect recently accessed a specific folder on a network. Which registry key should the investigator analyze to retrieve only the folder information (answer) BagMRU 20.What is a characteristic of Unicode UTF-32 (answer) Fixed-width encoding

  • / 3

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: WGU EXAMS
Added: Sep 5, 2025
Description:

1 / WGU C702 - Forensics and Network Intrusion Exam 2022 1.Which documentation should a forensic examiner prepare prior to a dy- namic analysis (answer) The full path and location of the file being...

Get this document $30.00