WGU C702 CHFI and OA Latest Update 2024- 2025 200+ Questions and Verified Correct Answers Guaranteed A+ ______ is a 128 bit unique reference number used as an identifier in computer
software? - CORRECT ANSWER: Global Unique Identifier (GUID)
________ command is used to display the network configuration of the NICs on the
system. - CORRECT ANSWER: ipconfig /all
________ is the standard investigative model used by the FBI when conducting investigations against major criminal organizations. - CORRECT ANSWER: Enterprise Theory of Investigation (ETI).
A chain of custody is a critical document in the computer forensics investigation process because the document provides legal validation of appropriate evidence
handling. - CORRECT ANSWER: True.
A computer forensic examiner can investigate any crime as long as he or she takes
detailed notes and follows the appropriate processes. - CORRECT ANSWER: False.
An email client connects with a POP3 server via which of the following? - CORRECT
ANSWER: Port 110.
An investigator may commit some common mistakes while collecting data from the system that result in the loss of critical evidence. Which of the following is NOT a
mistake that investigators commonly make? - CORRECT ANSWER: Use of correct
cables and cabling techniques.
Because they are always changing, the information in the registers or the processor
cache are the most volatile data. - CORRECT ANSWER: True.
Codes of ethics are the principles stated to describe the expected behavior of an investigator while handling a case. Which of the following is NOT a principle that a computer forensic investigator must follow? - CORRECT ANSWER: Provide personal or prejudiced opinions.
Computer Forensics deals with the process of finding _____ related to a digital crime to find the culprits and initiate legal action against them. - CORRECT ANSWER: Evidence.
Courts call knowledgable persons to testify to the accuracy of the investigative process.These people who tesify are known as the: - CORRECT ANSWER: Expert witnesses.
Cybercrimes can be classified into the following two types of attacks, based on the line of attack. - CORRECT ANSWER: Internal and External. 1 / 3
Digital devices store data about session such as user and type of connection. -
CORRECT ANSWER: True.
Espionage, theft of intellectual property, manipulation of records, and trojan horse
attacks are examples of what? - CORRECT ANSWER: Insider attack or primary
attacks.
External attacks occur when there are inadequate information-security policies and
procedures. - CORRECT ANSWER: True.
For Forensics Analysis, which of the following MySQL Utility Programs is used to
export metadata, data, or both from one or more databases? - CORRECT ANSWER:
mysqldbexport
Forensic data duplication involves the creation of a file that has every bit of information
from the source in a raw bit-stream format. - CORRECT ANSWER: True.
Forensic readiness includes technical and nontechnical actions that maximize an
organization's competence to use digital evidence. - CORRECT ANSWER: True.
Forensic readiness refers to: - CORRECT ANSWER: An organization's ability to make optimal use of digital evidence in a limited time period and with minimal investigation costs.
How can an attacker exploit a network? - CORRECT ANSWER: Through wired or
wireless connections.
How large is the partition table structure that stores information about the partitions
present on the hard disk? - CORRECT ANSWER: 64-byte.
How many bit values does HFS use to address allocation blocks? - CORRECT
ANSWER: 16
How many bits are used by the MBR partition scheme for storing LBAs (Logical Block
Addresses) and the size information on a 512-byte sector? - CORRECT ANSWER: 32
bits
How should expert witnesses conduct themselves while presenting testimony to any
court or attorney? - CORRECT ANSWER: Avoid leaning and develop self-confidence.
Identify the following Cloud computing services that enable subscribers to use fundamental IT resources such as computing power, virtualization, data storage,
network, and so on- on demand. - CORRECT ANSWER: Infrastructure-as-a-service
(IaaS)
- / 3
Identify the following which was launched by the National Institute of Standards and Technology (NIST), that establishes a "methodology for testing computer forensics software tools by development of general tool specifications, test procedures, test criteria, test sets, and test hardware." - CORRECT ANSWER: Computer Forensic Tool Testing Project (CFTTP)
Identify which code can be used to obtain the International Mobile Equipment Identifier
(IMEI) number on a mobile phone. - CORRECT ANSWER: *#06#
In Anti Forensics Techniques, which of the following techniques is used to hide a secret message within an ordinary message and extract it at the destination to maintain
confidentiality of data? - CORRECT ANSWER: Steganography
In Detecting Rootkits, the following technique is used to compare characteristics of all system processes and executable files with a database of known rootkit fingerprints. -
CORRECT ANSWER: Signature-Based Detection
In Event Correlation Approaches, which approach is used to monitor the computers and computer users behavior and provide an alert if something anomalous is found? -
CORRECT ANSWER: Role-based approach
In forensics laws, "authenticating or identifying evidences" comes under which rule? -
CORRECT ANSWER: Rule 901.
In Linux Standard Tools, forensic investigators use the following build-in Linux Commands to copy data from a disk drive: - CORRECT ANSWER: dd and dcfldd
In Port Monitoring, the following command is used to look for connections established
to unknown or suspicious IP addresses. - CORRECT ANSWER: Netstat -an
In sector, addressing _______ determines the address of the individual sector on the
disk. - CORRECT ANSWER: Cylinders, Heads, and Sectors (CHS)
in the GUID Partition Table, which Logical Block Address contains the Partition Entry
Array? - CORRECT ANSWER: LBA 2
In the Windows Event Log File internals, the following file is used to store the Databases related to the system: - CORRECT ANSWER: System.evtx
In what type of forensic examination do investigators perform an examination of logs to detect something that has already occurred in a network/device and determine what it
is? - CORRECT ANSWER: Postmortem
Intruders attempting to gain remote access to a system try to find the other systems connected to the network and visible to the compromised system. - CORRECT
ANSWER: True.
- / 3