WGU - C702 Forensics and Network Intrusion Exam Latest Update 2024-2025 150 Questions and Verified Correct Answers Guaranteed A+ 18 US Code 1029: - CORRECT ANSWER: Fraud and related activity in connection with access devices.
18 US Code 1030: - CORRECT ANSWER: Fraud and related activity in connection with computers.
A computer forensic expert makes sure that the following rules are upheld during an investigation process: - CORRECT ANSWER: 1. Preservation of evidence
- Prevention of contamination of evidence
- Extraction and preservation of evidence
- Accountability of evidence
- Limited interference of the crime scene on normal life
- Ethics of investigation
Application Security [IT Security] - CORRECT ANSWER: Applications should be
secured to overcome security weaknesses, vulnerabilities, and threats. Any loopholes in Web-based and other custom applications serve as opportunities for attackers.
arp -a: - CORRECT ANSWER: Display the current ARP entries. This includes the IP and MAC addresses.
arp -d: - CORRECT ANSWER: Delete the host specified by the IP Address;
arp -s: - CORRECT ANSWER: Add the host and associates the IP Address with the physical address.
arp -v: - CORRECT ANSWER: Display the information verbosely.
ARP Table Commands: - CORRECT ANSWER: arp -d; arp -a; arp -s; arp -v;
ASCLD [American Society of Crime Laboratory Directors]: - CORRECT ANSWER: To promote the effectiveness of crime laboratory leaders throughout the world by facilitating communication among members, sharing critical information, providing relevant training, promoting crime laboratory accreditation/certification, and encouraging scientific and managerial excellence in the global forensic community
Aspects of Organizational Security - CORRECT ANSWER: IT Security;
Physical Security; 1 / 2
Financial Security; Legal Security;
Audit Policy Event ID's: - CORRECT ANSWER: Event ID 4904: An attempt was made to register a security event source.
Event ID 4902: The Per-user audit policy table was created.
Bad Cluster: - CORRECT ANSWER: Is a sector on a computer's disk drive or flash memory that is either inacessible or unwriteable due to permanent damage, such as physical damage to the disk surface or failed flash memory transistors
Bit Depth: - CORRECT ANSWER: Is either the number of bits used to indicate the color of a single pixel, in a bitmapped image or video frame buffer, or the number of bits used for each color component of a single pixel
Bit Stream copy: - CORRECT ANSWER: A bit by bit copy of the original storage medium and or evidence
Brute-Force Attack: - CORRECT ANSWER: This attack, the attacker tries every possible combination of characters until the correct password is found. It's a very slow method and takes a large amount of time for longer passwords
Buffer Overflow: - CORRECT ANSWER: is an anomaly where a program, while writing data to a buffer, overruns the buffer's boundary and overwrites adjacent memory. This is a special case of violation of memory safety. Buffer overflows can be triggered by inputs that are designed to execute code, or alter the way the program operates. This may result in erratic program behavior, including memory access errors, incorrect results, a crash, or a breach of system security.
Business case - CORRECT ANSWER: The justification to upper management or a
lender for purchasing new equipment, software, or other tools when upgrading your facility
Chain of Custody: - CORRECT ANSWER: A method for documenting the history and possession of a sample from the time of collection, though analysis and data reporting, to its final disposition
Chain of Custody: - CORRECT ANSWER: Chain of custody [CoC], in legal contexts, refers to the chronological documentation or paper trail, showing the seizure, custody, control, transfer between sender and receiver, analysis, and disposition of physical or electronic evidence
Client mis-association: - CORRECT ANSWER: Client Mis-association can be accidental, deliberate [for example, done to bypass corporate firewall] or it can result from deliberate attempts on wireless clients to lure them into connecting to attacker's Access Point
- / 2