
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 2
Dark Web Forensics CHFI Practice Questions (Page 4)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 16–20
- 16
A forensic examiner is analyzing a suspect's hard drive and finds a file with a .onion URL. The examiner wants to determine if the suspect accessed the dark web. Which finding would provide the strongest evidence of Tor usage?
Select an answer first - 17
An investigator is tracking a ransomware group that communicates on a dark web forum and demands payment in Bitcoin. The investigator has identified a Bitcoin address used by the group. Which step would be most useful to determine if the group has cashed out the funds?
Select an answer first - 18
A cybersecurity analyst is tasked with monitoring for mentions of their company's stolen data on the dark web. Which approach is most appropriate for this task?
Select an answer first - 19
An investigator is using OSINT to gather information about a dark web vendor's identity. The vendor uses a unique username across multiple platforms. What is the most effective OSINT technique?
Select an answer first - 20
Why might a user choose to use a VPN in addition to the Tor Browser when accessing the dark web?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.