
EC-CouncilComputer Hacking Forensic Investigator
Domain 6Objective 2
Email and Social Media Forensics CHFI Practice Questions (Page 3)
Part of the Cloud and Communication Forensics domain, which makes up ~14% of our current practice bank.
55questions here
11free pages
11concepts
Questions 11–15
- 11
A forensic investigator is examining a Windows laptop used by a suspect to access Twitter. The suspect used the Twitter web interface, not the app. Which artifact would provide the most direct evidence of the suspect's Twitter activity, such as direct messages and posted tweets?
Select an answer first - 12
A forensic investigator is building a digital footprint of a suspect using publicly available social media information. The investigator finds that the suspect's Twitter profile is public, but the suspect's Facebook profile is private. The investigator needs to document evidence for a court case. Which of the following is the most appropriate course of action?
Select an answer first - 13
When collecting evidence from social media, what is the primary legal consideration that must be addressed?
Select an answer first - 14
A suspect used a public computer at a library to check a personal webmail account and then deleted the browser history. The investigator needs to recover evidence of the webmail activity. Which technique is most likely to yield residual data?
Select an answer first - 15
In Microsoft Outlook, which file stores the user's email messages, contacts, and calendar items in a single database?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.