
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 2
Linux and Mac Forensics CHFI Practice Questions (Page 3)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
12concepts
Questions 11–15
- 11
A forensic examiner is investigating a macOS system and needs to determine if FileVault was enabled and when the system was last unlocked. Which artifacts should be examined?
Select an answer first - 12
A Linux administrator notices a suspicious process running on a server. The administrator needs to determine which executable file the process is running from. Which command would provide this information?
Select an answer first - 13
During a forensic examination of a Linux system, an investigator needs to recover a deleted file that was stored in the /home/user directory. The file system is ext4 and the system has been powered off. Which approach is most likely to recover the deleted file?
Select an answer first - 14
A forensic examiner is investigating a Linux system where an attacker is suspected of adding a user to the sudo group. Which files and logs should be examined to confirm this?
Select an answer first - 15
A Linux system administrator suspects that an unauthorized user account was created on a server. Which file should be examined first to confirm the existence of the account and its UID?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.