
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 2
Linux and Mac Forensics CHFI Practice Questions (Page 2)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
12concepts
Questions 6–10
- 6
An investigator needs to identify which processes on a macOS system have made network connections. Which command or tool would provide the most comprehensive view?
Select an answer first - 7
An investigator is analyzing a Linux system that was compromised. The attacker used a rootkit that hides processes from `ps` and `netstat`. Which technique would be most effective in identifying the hidden processes and their network connections?
Select an answer first - 8
An investigator is reconstructing the activities of a macOS user who is suspected of unauthorized access. The investigator wants to see a chronological record of system and user events. Which tool or command would provide the most comprehensive unified log access?
Select an answer first - 9
A forensic examiner is investigating a Mac that was used to access sensitive corporate data. The user claims they only used Safari, but the examiner suspects other browsers were used. Which approach would best confirm or refute this?
Select an answer first - 10
A forensic investigator is examining a Linux system that was running an ext4 file system. The investigator needs to recover deleted files, but the system has been used since the deletion, and the investigator must also preserve the integrity of the evidence. Which approach best balances the need for recovery and evidence preservation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.