
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 2
Linux and Mac Forensics CHFI Practice Questions (Page 4)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
12concepts
Questions 16–20
- 16
A forensic examiner is analyzing a macOS system that was used to download a suspicious file from the internet. The examiner needs to determine when the file was downloaded and whether it was quarantined by macOS. Which artifact would provide this information?
Select an answer first - 17
In Linux, the /proc directory is often examined during forensic analysis. What is the primary purpose of /proc?
Select an answer first - 18
A Linux server is behaving abnormally. The investigator needs to identify any suspicious processes and correlate them with network connections. Which command sequence would be most effective?
Select an answer first - 19
A security analyst notices unusual outbound network traffic from a Linux server. The analyst suspects a malicious process is running. Which command would provide the most comprehensive view of running processes along with their network connections?
Select an answer first - 20
A forensic examiner is analyzing a macOS system that has an APFS volume. The examiner needs to recover a deleted file that was stored in the user's Documents folder. The system has been used since the deletion. Which approach is most likely to succeed while maintaining forensic integrity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.