Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free WGU Digital Forensics in Cybersecurity Digital-Forensics-in-Cybersecurity Exam Questions

Page: 1 / 8 Total 74 questions

Want more questions? Get Premium Access.

Question 1

How is the Windows swap file, also known as page file, used?

Correct Answer: C. Augments the RAM
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

The Windows swap file, or page file, is a system file used to extend physical memory by storing data that cannot fit into the RAM. When RAM is full, the OS swaps inactive data pages to this file, thus augmenting RAM capacity.

It does not replace bad sectors; that function is for disk management utilities.

It is not primarily for security but for memory management.

It is not reserved exclusively for system files but is used dynamically for memory paging.


Microsoft's official documentation and forensic guides like NIST SP 800-86 describe the page file's role in virtual memory management and its importance in forensic analysis because it may contain fragments of memory and sensitive information.

Question 2

Which storage format is a magnetic drive?

Correct Answer: B. SATA
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

SATA (Serial ATA) refers to an interface standard commonly used for connecting magnetic hard disk drives (HDDs) and solid-state drives (SSDs) to a computer. The term SATA itself describes the connection, but most HDDs that use SATA as an interface are magnetic drives.

CD-ROM and Blu-ray are optical storage media, not magnetic.

SSD (Solid State Drive) uses flash memory, not magnetic storage.

Magnetic drives rely on spinning magnetic platters, which are typically connected via SATA or other interfaces.

This differentiation is emphasized in digital forensic training and hardware documentation, including those from NIST and forensic hardware textbooks.


Question 3

An organization is determined to prevent data leakage through steganography. It has developed a workflow that all outgoing data must pass through. The company will implement a tool as part of the workflow to check for hidden data.

Which tool should be used to check for the existence of steganographically hidden data?

Correct Answer: C. Snow
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

Snow is a specialized steganalysis tool that detects and extracts hidden data encoded in whitespace characters within text files and other mediums. It is widely used in digital forensic investigations for detecting covert data hiding methods such as whitespace steganography.

Data Doctor is a general data recovery tool, not specialized in steganalysis.

FTK is a general forensic suite, not specifically designed for steganography detection.

MP3Stego is focused on audio steganography.

NIST and digital forensics literature recognize Snow as a valuable tool in workflows designed to detect hidden data in text or similar carriers.


Question 4

Which file stores local Windows passwords in the Windows\System32\ directory and is subject to being cracked by using a live CD?

Correct Answer: A. SAM
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

The SAM (Security Account Manager) file located in the Windows\System32\config directory stores hashed local user account passwords. It can be accessed and extracted using a live CD or bootable forensic tool, which allows the forensic investigator to bypass the running operating system and avoid altering the evidence.

IPSec is related to network security policies, not password storage.

HAL (Hardware Abstraction Layer) is a system file managing hardware interaction.

Ntidr is a boot loader file in Windows NT systems.

Cracking password hashes extracted from the SAM file is a common forensic practice to recover user passwords during investigations.


NIST Special Publication 800-86 and Windows forensic textbooks confirm that the SAM file is the repository of local password hashes accessible via forensic live CDs or imaging.

Question 5

Which law requires both parties to consent to the recording of a conversation?

Correct Answer: B. Electronic Communications Privacy Act (ECPA)
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

The Electronic Communications Privacy Act (ECPA) regulates interception and recording of electronic communications and generally requires the consent of both parties involved in a conversation for legal recordings.

This consent requirement protects privacy rights during investigations.

Non-compliance can lead to evidence being inadmissible or legal penalties.


ECPA provisions are detailed in legal frameworks governing digital privacy and forensics.

Question 6

Which law includes a provision permitting the wiretapping of VoIP calls?

Correct Answer: A. Communications Assistance to Law Enforcement Act (CALEA)
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

The Communications Assistance to Law Enforcement Act (CALEA) mandates telecommunications carriers to assist law enforcement in executing authorized wiretaps, including on Voice over IP (VoIP) calls, ensuring lawful interception capabilities.

CALEA requires built-in surveillance capabilities in communications systems.

It balances privacy rights with law enforcement needs.


CALEA is cited in digital forensics and cybersecurity standards relating to lawful interception capabilities.

Question 7

Which information is included in an email header?

Correct Answer: C. Content-Type
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

An email header contains metadata about the email including sender, receiver, routing information, and content details. The Content-Type header specifies the media type of the email body (e.g., text/plain, text/html, multipart/mixed), indicating how the email content should be interpreted.

Sender's MAC address is not typically included in email headers.

Number of pages is not relevant to email metadata.

Message-Digest is a term related to cryptographic hashes but is not a standard email header field.


RFC 5322 and forensic email analysis references outline that email headers contain fields like Content-Type describing the format of the message content, essential for proper parsing and forensic examination.

Question 8

Which description applies to the Advanced Forensic Format (AFF)?

Correct Answer: C. An open file standard used by Sleuth Kit and Autopsy
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

The Advanced Forensic Format (AFF) is an open file format designed for storing disk images and related forensic metadata. It was developed by the Sleuth Kit community and is supported by forensic tools such as Sleuth Kit and Autopsy. AFF allows efficient storage, compression, and metadata annotation, which makes it suitable for forensic investigations.

AccessData is known for FTK format, not AFF.

iLook uses proprietary formats unrelated to AFF.

Guidance Software developed the EnCase Evidence File (E01) format.

AFF is widely recognized in open-source forensic toolchains.


The AFF format and its use with Sleuth Kit and Autopsy are documented in digital forensics literature and the AFF official documentation, as endorsed by the NIST and forensic tool developer communities.

Question 9

Which type of storage format should be transported in a special bag to reduce electrostatic interference?

Correct Answer: B. Magnetic media
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

Magnetic media such as hard drives and magnetic tapes are sensitive to electrostatic discharge (ESD), which can damage data. They must be transported in anti-static bags or containers to reduce the risk of electrostatic interference.

SSDs and flash drives are less vulnerable to ESD but still benefit from proper packaging.

Proper handling protocols prevent unintentional data loss or corruption.


NIST SP 800-101 and forensic evidence handling standards specify anti-static packaging for magnetic storage media.

Question 10

Which characteristic applies to solid-state drives (SSDs) compared to magnetic drives?

Correct Answer: A. They are less susceptible to damage
Explanation:

Comprehensive and Detailed Explanation From Exact Extract:

Solid-state drives (SSDs) use flash memory and have no moving mechanical parts, making them more resistant to physical shock and damage compared to magnetic drives, which rely on spinning platters.

This resilience makes SSDs favorable in environments with higher physical risk.

However, data recovery from SSDs can be more complex due to wear-leveling and TRIM features.


NIST and forensic hardware guides highlight SSD durability advantages over traditional magnetic storage.