1 / 10
WGU C702 Forensics and Network Intrusion Exam 2022 1.How large is the partition table structure that stores information about the partitions present on the hard disk (answer) 64 bytes 2.On Macintosh computers, which architecture utilizes EFI to initialize the hardware interfaces after the BootROM performs POST (answer) Intel- based Macin- tosh Computers
3.:What component of a typical FAT32 file system occupies the largest
part of a partition and stores the actual files and directories (answer) Data Area 4.What is a technology that uses multiple smaller disks simultaneously that function as a single large volume (answer) RAID 5.What is the maximum file system size in ext3 (answer) 32 TB 6.What is the maximum file system size in ext4 (answer) 1 EiB
7.:What layer of web application architecture is responsible for the core
functioning of the system and includes logic and applications, such as .NET, used by developers to build websites according to client requirements (answer) - business layer 8.What stage of the Linux boot process includes the task of loading the virtual root file system created by the initrd image and executes the Linuxrc program (answer) Kernel Stage 1 / 3
2 / 10
9.What UFS file system part comprises a collection, including a header with statistics and free lists, a number of inodes containing file attributes, and a number of data blocks (answer) cylinder group 10.Which attribute ID does NTFS set as a flag after encrypting a file where the Data Decryption Field (DDF) and Data Recovery Field (DRF) is stored (answer) 0x100 11.Which cmdlet can investigators use in Windows PowerShell to analyze the GUID Partition Table data structure of the hard disk (answer) Get- GPT 12.Which cmdlet can investigators use in Windows PowerShell to analyze the GUID Partition Table to find the exact type of boot sector and display the partition object (answer) Get-PartitionTable 13.Which field type refers to the volume descriptor as a supplementary (answer) - Number 2 14.Which HFS volume structure is the starting block of the volume bitmap?-
: Logical Block 3
15.Which inode field determines what the inode describes and the permis- sions that users have to it (answer) Mode 2 / 3
3 / 10
16.Which inode field enables the file system to correctly allow the right sort of access (answer) Owner Information 17.Which item describes the following UEFI boot process phase?The phase of EFI consisting of clearing the UEFI program from memory, transferring the UEFI program to the OS, and updating the OS calls for the
run time service using a small part of the memory.: Run Time Phase
18.:Which of the following basic partitioning tools displays details
about GPT partition tables in Linux OS (answer) GNU Parted 19.Which of the following basic partitioning tools displays details about GPT partition tables in Macintosh OS (answer) Disk Utility 20.Which of the following Federal Rules of Evidence contains Rulings on Evidence (answer) Rule 103
21.What are the five UEFI Boot Process Phases: Security
Phase Pre-EFI Initialization Phase Driver Execution Phase Boot Device Selection Phase Run Time Phase 22.Which of the following stakeholders is responsible for conducting foren- sic examinations against allegations made regarding wrongdoings, found vulnerabilities, and attacks over the cloud (answer) Investigators
23.:Which of the two parts of the Linux file system architecture has the
memory space where the system supplies all services through an executed system call (answer) Kernel Space
- / 3