WGU C702 CHFI and OA Latest Update 2024-

Study Guides Aug 17, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

WGU C702 CHFI and OA Latest Update 2024- 2025 200+ Questions and Verified Correct Answers Guaranteed A+ ______ is a 128 bit unique reference number used as an identifier in computer

software? - CORRECT ANSWER: Global Unique Identifier (GUID)

________ command is used to display the network configuration of the NICs on the

system. - CORRECT ANSWER: ipconfig /all

________ is the standard investigative model used by the FBI when conducting investigations against major criminal organizations. - CORRECT ANSWER: Enterprise Theory of Investigation (ETI).

A chain of custody is a critical document in the computer forensics investigation process because the document provides legal validation of appropriate evidence

handling. - CORRECT ANSWER: True.

A computer forensic examiner can investigate any crime as long as he or she takes

detailed notes and follows the appropriate processes. - CORRECT ANSWER: False.

An email client connects with a POP3 server via which of the following? - CORRECT

ANSWER: Port 110.

An investigator may commit some common mistakes while collecting data from the system that result in the loss of critical evidence. Which of the following is NOT a

mistake that investigators commonly make? - CORRECT ANSWER: Use of correct

cables and cabling techniques.

Because they are always changing, the information in the registers or the processor

cache are the most volatile data. - CORRECT ANSWER: True.

Codes of ethics are the principles stated to describe the expected behavior of an investigator while handling a case. Which of the following is NOT a principle that a computer forensic investigator must follow? - CORRECT ANSWER: Provide personal or prejudiced opinions.

Computer Forensics deals with the process of finding _____ related to a digital crime to find the culprits and initiate legal action against them. - CORRECT ANSWER: Evidence.

Courts call knowledgable persons to testify to the accuracy of the investigative process.These people who tesify are known as the: - CORRECT ANSWER: Expert witnesses.

Cybercrimes can be classified into the following two types of attacks, based on the line of attack. - CORRECT ANSWER: Internal and External. 1 / 3

Digital devices store data about session such as user and type of connection. -

CORRECT ANSWER: True.

Espionage, theft of intellectual property, manipulation of records, and trojan horse

attacks are examples of what? - CORRECT ANSWER: Insider attack or primary

attacks.

External attacks occur when there are inadequate information-security policies and

procedures. - CORRECT ANSWER: True.

For Forensics Analysis, which of the following MySQL Utility Programs is used to

export metadata, data, or both from one or more databases? - CORRECT ANSWER:

mysqldbexport

Forensic data duplication involves the creation of a file that has every bit of information

from the source in a raw bit-stream format. - CORRECT ANSWER: True.

Forensic readiness includes technical and nontechnical actions that maximize an

organization's competence to use digital evidence. - CORRECT ANSWER: True.

Forensic readiness refers to: - CORRECT ANSWER: An organization's ability to make optimal use of digital evidence in a limited time period and with minimal investigation costs.

How can an attacker exploit a network? - CORRECT ANSWER: Through wired or

wireless connections.

How large is the partition table structure that stores information about the partitions

present on the hard disk? - CORRECT ANSWER: 64-byte.

How many bit values does HFS use to address allocation blocks? - CORRECT

ANSWER: 16

How many bits are used by the MBR partition scheme for storing LBAs (Logical Block

Addresses) and the size information on a 512-byte sector? - CORRECT ANSWER: 32

bits

How should expert witnesses conduct themselves while presenting testimony to any

court or attorney? - CORRECT ANSWER: Avoid leaning and develop self-confidence.

Identify the following Cloud computing services that enable subscribers to use fundamental IT resources such as computing power, virtualization, data storage,

network, and so on- on demand. - CORRECT ANSWER: Infrastructure-as-a-service

(IaaS)

  • / 3

Identify the following which was launched by the National Institute of Standards and Technology (NIST), that establishes a "methodology for testing computer forensics software tools by development of general tool specifications, test procedures, test criteria, test sets, and test hardware." - CORRECT ANSWER: Computer Forensic Tool Testing Project (CFTTP)

Identify which code can be used to obtain the International Mobile Equipment Identifier

(IMEI) number on a mobile phone. - CORRECT ANSWER: *#06#

In Anti Forensics Techniques, which of the following techniques is used to hide a secret message within an ordinary message and extract it at the destination to maintain

confidentiality of data? - CORRECT ANSWER: Steganography

In Detecting Rootkits, the following technique is used to compare characteristics of all system processes and executable files with a database of known rootkit fingerprints. -

CORRECT ANSWER: Signature-Based Detection

In Event Correlation Approaches, which approach is used to monitor the computers and computer users behavior and provide an alert if something anomalous is found? -

CORRECT ANSWER: Role-based approach

In forensics laws, "authenticating or identifying evidences" comes under which rule? -

CORRECT ANSWER: Rule 901.

In Linux Standard Tools, forensic investigators use the following build-in Linux Commands to copy data from a disk drive: - CORRECT ANSWER: dd and dcfldd

In Port Monitoring, the following command is used to look for connections established

to unknown or suspicious IP addresses. - CORRECT ANSWER: Netstat -an

In sector, addressing _______ determines the address of the individual sector on the

disk. - CORRECT ANSWER: Cylinders, Heads, and Sectors (CHS)

in the GUID Partition Table, which Logical Block Address contains the Partition Entry

Array? - CORRECT ANSWER: LBA 2

In the Windows Event Log File internals, the following file is used to store the Databases related to the system: - CORRECT ANSWER: System.evtx

In what type of forensic examination do investigators perform an examination of logs to detect something that has already occurred in a network/device and determine what it

is? - CORRECT ANSWER: Postmortem

Intruders attempting to gain remote access to a system try to find the other systems connected to the network and visible to the compromised system. - CORRECT

ANSWER: True.

  • / 3

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: Study Guides
Added: Aug 17, 2025
Description:

WGU C702 CHFI and OA Latest Update 2024- 2025 200+ Questions and Verified Correct Answers Guaranteed A+ ______ is a 128 bit unique reference number used as an identifier in computer software? - COR...

Get this document $30.00