Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

WGU (D431/C840) Digital Forensics in Cybersecurity Course Exam - Topic 4 Question 9 Discussion

Actual exam question for WGU's WGU (D431/C840) Digital Forensics in Cybersecurity Course exam
Question #: 9
Topic #: 4
[All WGU (D431/C840) Digital Forensics in Cybersecurity Course Questions]

A forensics investigator is investigating a Windows computer which may be collecting data from other computers on the network.

Which Windows command line tool can be used to determine connections between machines?

Show Suggested Answer Hide Answer
Suggested Answer: D

Comprehensive and Detailed Explanation From Exact Extract:

Netstat is a standard Windows command line utility that displays active network connections, routing tables, and network interface statistics. It is widely used in forensic investigations to identify current and past TCP/IP connections, including IP addresses and port numbers associated with remote hosts. This information helps investigators identify if the suspect computer has active connections to other machines potentially used for data collection or command and control.

Telnet is a protocol used to connect to remote machines but does not display current network connections.

Openfiles shows files opened remotely but not network connection details.

Xdetect is not a standard Windows tool and not recognized in forensic investigations.


According to NIST SP 800-86 and SANS Digital Forensics guidelines, netstat is an essential tool for gathering network-related evidence during system investigations.

Contribute your Thoughts:

0/2000 characters
Sonia
2 days ago
I'm not entirely sure, but I remember something about Telnet being used for remote connections. Could it be that one?
upvoted 0 times
...
Bok
7 days ago
I think the answer might be Netstat since it shows active connections and listening ports, right?
upvoted 0 times
...

Save Cancel