Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 3Objective 2

Linux and Mac Forensics CHFI Practice Questions (Page 3)

Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.

31questions here
7free pages
12concepts

Questions 11–15

  1. 11application · medium

    A forensic examiner is investigating a macOS system and needs to determine if FileVault was enabled and when the system was last unlocked. Which artifacts should be examined?

    Select an answer first
  2. 12application · medium

    A Linux administrator notices a suspicious process running on a server. The administrator needs to determine which executable file the process is running from. Which command would provide this information?

    Select an answer first
  3. 13application · medium

    During a forensic examination of a Linux system, an investigator needs to recover a deleted file that was stored in the /home/user directory. The file system is ext4 and the system has been powered off. Which approach is most likely to recover the deleted file?

    Select an answer first
  4. 14application · medium

    A forensic examiner is investigating a Linux system where an attacker is suspected of adding a user to the sudo group. Which files and logs should be examined to confirm this?

    Select an answer first
  5. 15application · easy

    A Linux system administrator suspects that an unauthorized user account was created on a server. Which file should be examined first to confirm the existence of the account and its UID?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.