
EC-CouncilCertified Cybersecurity Technician
Domain 7Objective 2
Computer Forensics CCT Practice Questions (Page 1)
Part of the Incident Response and Computer Forensics domain, which makes up ~10% of our current practice bank.
56questions here
12free pages
13concepts
Questions 1–5
- 1
During a memory forensics analysis, an examiner finds a suspicious process that is not visible in the process list from the operating system. The examiner suspects the process is hidden using a rootkit technique. Which memory forensics technique is MOST effective for detecting this hidden process?
Select an answer first - 2
A forensic examiner is analyzing an NTFS volume and discovers that a file's MFT entry is marked as deleted, but the file's data clusters are still marked as allocated. What is the most likely reason for this condition?
Select an answer first - 3
Which file system is commonly used by modern Windows operating systems?
Select an answer first - 4
An investigator is analyzing a forensic image of a Windows system and needs to find evidence of a specific file that was deleted and then overwritten. Which technique is most likely to recover remnants of the file?
Select an answer first - 5
During a forensic investigation, an examiner transfers a seized hard drive from the evidence locker to the lab. The drive is later analyzed, and the findings are presented in court. What documentation is essential to prove the evidence was not tampered with during this transfer?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.