Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
An organization believes that a company-owned mobile phone has been compromised.
Which software should be used to collect an image of the phone as digital evidence?
Comprehensive and Detailed Explanation From Exact Extract:
Forensic Toolkit (FTK) is a widely recognized and trusted software suite in digital forensics used to acquire and analyze forensic images of devices, including mobile phones. FTK supports the creation of bit-by-bit images of digital evidence, ensuring the integrity and admissibility of the evidence in legal contexts. This imaging process is crucial in preserving the original state of the device data without alteration.
FTK enables forensic investigators to perform logical and physical acquisitions of mobile devices.
It maintains the integrity of the evidence by generating cryptographic hash values (MD5, SHA-1) to prove that the image is an exact copy.
Other options such as PTFinder or Forensic SIM Cloner focus on specific tasks like SIM card cloning or targeted data extraction but do not provide full forensic imaging capabilities.
Data Doctor is more aligned with data recovery rather than forensic imaging.
According to standard digital forensics methodologies outlined by NIST Special Publication 800-101 (Guidelines on Mobile Device Forensics) and the SANS Institute Digital Forensics and Incident Response guides, forensic tools used to acquire mobile device images must be capable of bit-stream copying with hash verification, which FTK provides.
Which description applies to the Advanced Forensic Format (AFF)?
Comprehensive and Detailed Explanation From Exact Extract:
The Advanced Forensic Format (AFF) is an open file format designed for storing disk images and related forensic metadata. It was developed by the Sleuth Kit community and is supported by forensic tools such as Sleuth Kit and Autopsy. AFF allows efficient storage, compression, and metadata annotation, which makes it suitable for forensic investigations.
AccessData is known for FTK format, not AFF.
iLook uses proprietary formats unrelated to AFF.
Guidance Software developed the EnCase Evidence File (E01) format.
AFF is widely recognized in open-source forensic toolchains.
The AFF format and its use with Sleuth Kit and Autopsy are documented in digital forensics literature and the AFF official documentation, as endorsed by the NIST and forensic tool developer communities.
Which Windows component is responsible for reading the boot.ini file and displaying the boot loader menu on Windows XP during the boot process?
Comprehensive and Detailed Explanation From Exact Extract:
NTLDR (NT Loader) is the boot loader for Windows NT-based systems including Windows XP. It reads the boot.ini configuration file and displays the boot menu, initiating the boot process.
Later Windows versions (Vista and above) replaced NTLDR with BOOTMGR.
Understanding boot components assists forensic investigators in boot process analysis.
Microsoft technical documentation and forensic training materials outline NTLDR's role in legacy Windows systems.
A user at a company attempts to hide the combination to a safe that stores confidential information in a data file called vacationdetails.doc.
What is vacationdetails.doc called, in steganographic terms?
Comprehensive and Detailed Explanation From Exact Extract:
In steganography, the file that hides secret information is called the carrier. The carrier file appears normal and contains embedded hidden data (the payload).
Payload refers to the actual secret data hidden inside the carrier.
Snow refers to random noise or artifacts, often in images or files.
Channel refers to the medium or communication path used to transmit data.
Thus, vacationdetails.doc is the carrier file containing the hidden information.
Standard steganography literature and forensic documentation define the carrier as the file used to conceal payload data.
Which law includes a provision permitting the wiretapping of VoIP calls?
Comprehensive and Detailed Explanation From Exact Extract:
The Communications Assistance to Law Enforcement Act (CALEA) mandates telecommunications carriers to assist law enforcement in executing authorized wiretaps, including on Voice over IP (VoIP) calls, ensuring lawful interception capabilities.
CALEA requires built-in surveillance capabilities in communications systems.
It balances privacy rights with law enforcement needs.
CALEA is cited in digital forensics and cybersecurity standards relating to lawful interception capabilities.
74 questions covering all exam domains, starting from $20
Exam domains verified against: Official WGU Digital-Forensics-in-Cybersecurity exam guide, last checked August 2026.
This domain evaluates the abilities of Cybersecurity Analysts and centers on the essential role that digital forensics plays within security operations. It addresses the methods used to investigate cyber events, interpret digital evidence, and determine how the results contribute to legal processes and organizational decisions.
This domain evaluates the capabilities of Cybersecurity Analysts and concentrates on examining gathered evidence through recognized forensic tools. It involves analyzing disks, file structures, system logs, and other digital sources while following standard investigation procedures that maintain precision and data integrity.
This domain evaluates the proficiency of Digital Forensics Technicians and focuses on retrieving evidence from deleted data, concealed information, and various system artifacts. It covers locating significant digital remnants, restoring usable material, and understanding the storage areas where system traces remain.
This domain evaluates the ability of Cybersecurity Analysts to prepare incident reports that convey the results of a forensic investigation. It involves organizing findings, presenting clear summaries, and delivering information to organizational leaders in a professional and coherent manner.
This domain evaluates the knowledge of Digital Forensics Technicians and centers on the legal frameworks and procedural rules that influence forensic practices. It covers recognizing applicable laws, organizational policies, and industry standards that ensure the investigative process remains valid, compliant, and reliable.
Sample question from this domain above: Q5
Common questions about the exam itself