
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 2
Linux and Mac Forensics CHFI Practice Questions (Page 1)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
12concepts
Questions 1–5
- 1
During a Linux forensic examination, you need to locate system-wide configuration files that affect the boot process and user environment. Which directory in the standard Linux hierarchy is the primary location for such configuration files?
Select an answer first - 2
An investigator is examining a Linux system where a deleted file's slack space may contain remnants of a password. The file system is ext4. Which method would be most appropriate to extract data from slack space?
Select an answer first - 3
A forensic examiner is analyzing a macOS system and needs to locate user-specific application data, such as browser profiles and application preferences. Which directory should be examined?
Select an answer first - 4
A forensic examiner is analyzing a macOS system and needs to determine whether FileVault was enabled at the time of acquisition. Which artifact would provide this information?
Select an answer first - 5
In Linux file system forensics, what is 'slack space'?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.