WGU Digital Forensics in Cybersecurity (D431/C840) Course Exam WGU (D431/C840) Digital Forensics in Cybersecurity Course Exam Questions

Page: 1 / 14
Total 74 questions
Question 1

Susan was looking at her credit report and noticed that several new credit cards had been opened lately in her name. Susan has not opened any of the credit card accounts herself.

Which type of cybercrime has been perpetrated against Susan?



Answer : A

Comprehensive and Detailed Explanation From Exact Extract:

Identity theft occurs when an attacker unlawfully obtains and uses another person's personal information to open accounts, access credit, or commit fraud. The opening of credit cards without the victim's consent is a classic example.

SQL injection is a web application attack method that does not directly relate to this case.

Cyberstalking involves harassment via digital means and is unrelated.

Malware is malicious software and may be used to facilitate identity theft but is not the crime itself.


According to the U.S. Federal Trade Commission (FTC) definitions and NIST Cybersecurity Framework, identity theft is defined as the unauthorized use of someone's personal information for fraudulent purposes, perfectly matching Susan's situation.

Question 2

What is one purpose of steganography?



Answer : B

Comprehensive and Detailed Explanation From Exact Extract:

Steganography is used to conceal information within other seemingly innocuous data, such as embedding messages inside image files, allowing secret delivery of information without detection.

Unlike encryption, steganography hides the existence of the message itself.

It is an anti-forensic technique used to evade detection.


NIST and digital forensics literature describe steganography as covert communication methodology.

Question 3

Which Windows component is responsible for reading the boot.ini file and displaying the boot loader menu on Windows XP during the boot process?



Answer : B

Comprehensive and Detailed Explanation From Exact Extract:

NTLDR (NT Loader) is the boot loader for Windows NT-based systems including Windows XP. It reads the boot.ini configuration file and displays the boot menu, initiating the boot process.

Later Windows versions (Vista and above) replaced NTLDR with BOOTMGR.

Understanding boot components assists forensic investigators in boot process analysis.


Microsoft technical documentation and forensic training materials outline NTLDR's role in legacy Windows systems.

Question 4

Which file system is supported by Mac?



Answer : C

Comprehensive and Detailed Explanation From Exact Extract:

Mac systems traditionally use the Hierarchical File System Plus (HFS+), which supports features such as journaling and metadata handling suited for Mac OS environments. Newer versions use APFS but HFS+ remains relevant.

NTFS is primarily a Windows file system.

EXT4 is a Linux file system.

FAT32 is a generic cross-platform file system but lacks advanced features.


Apple and NIST documentation confirm HFS+ as a Mac-supported file system for forensic analysis.

Question 5

The human resources manager of a small accounting firm believes he may have been a victim of a phishing scam. The manager clicked on a link in an email message that asked him to verify the logon credentials for the firm's online bank account.

Which digital evidence should a forensic investigator collect to investigate this incident?



Answer : B

Comprehensive and Detailed Explanation From Exact Extract:

The browser cache stores recently accessed web pages, images, and cookies, which may include phishing site content and related activity. Investigators analyzing phishing attacks collect browser cache data to reconstruct the victim's web activity and detect malicious sites.

Cached web pages help corroborate victim statements and establish timelines.

Browser history and cache are volatile and must be preserved promptly.


According to NIST SP 800-101 and forensic guides, browser cache is critical in investigating phishing and web-based attacks.

Question 6

Which policy is included in the CAN-SPAM Act?



Answer : A

Comprehensive and Detailed Explanation From Exact Extract:

The CAN-SPAM Act requires that commercial emails include a clear and conspicuous mechanism allowing recipients to opt out of receiving future emails. This opt-out method cannot require payment or additional steps that would discourage recipients.

The act aims to reduce unsolicited commercial emails and spam.

Compliance is critical for lawful email marketing and forensic investigations involving email misuse.


Question 7

How do forensic specialists show that digital evidence was handled in a protected, secure manner during the process of collecting and analyzing the evidence?



Answer : B

Comprehensive and Detailed Explanation From Exact Extract:

The chain of custody is a documented, chronological record detailing the seizure, custody, control, transfer, analysis, and disposition of evidence. Maintaining this record proves that the evidence was protected and unaltered, which is essential for court admissibility.

Each transfer or access must be logged with date, time, and handler.

Breaks in the chain can compromise the legal validity of evidence.


According to NIST and forensic best practices, the chain of custody documentation is mandatory for reliable evidence handling.

Page:    1 / 14   
Total 74 questions