Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 3Objective 2

Linux and Mac Forensics CHFI Practice Questions (Page 5)

Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.

31questions here
7free pages
12concepts

Questions 21–25

  1. 21expert · hard

    A Linux server was compromised, and the attacker used a reverse shell to maintain access. The investigator needs to identify the command used to establish the reverse shell and the external IP it connected to. Which evidence source would be most useful?

    Select an answer first
  2. 22application · medium

    An investigator is examining a macOS user's activity to determine which websites were visited. The user primarily uses Safari. Where should the investigator look for the most detailed browsing history?

    Select an answer first
  3. 23application · medium

    A network administrator is investigating a potential intrusion on a Linux server. The administrator needs to determine which IP addresses have established active connections to the server. Which command would provide a list of current network connections?

    Select an answer first
  4. 24application · medium

    A forensic examiner is analyzing a macOS system and needs to determine which applications were downloaded from the internet and when. Which artifact would provide this information?

    Select an answer first
  5. 25expert · hard

    A forensic examiner is investigating a Mac where the user is suspected of using a VPN to hide their activity. Which artifacts would provide the most reliable evidence of VPN usage?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.