
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 2
Linux and Mac Forensics CHFI Practice Questions (Page 6)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
12concepts
Questions 26–30
- 26
When performing forensic analysis on a Linux system, you need to recover a file that was deleted from an ext4 filesystem. What is the most appropriate approach?
Select an answer first - 27
A forensic analyst is investigating a macOS system that may have been used to launch a network attack. The analyst needs to identify which process initiated outbound connections. Which command or tool would be most effective?
Select an answer first - 28
A security team is investigating a Linux server that was compromised. The attacker created a new user account and used it to establish an SSH connection. The team needs to determine the exact time of account creation and the source IP of the SSH connection. Which combination of evidence would provide the most reliable timeline?
Select an answer first - 29
A forensic investigator wants to review authentication-related events on a Linux system, such as successful and failed login attempts. Which log file is most likely to contain this information?
Select an answer first - 30
An investigator is reconstructing the actions of a macOS user who is suspected of exfiltrating data. The investigator has access to the user's Mac and needs to determine if any files were transferred via AirDrop or external storage. Which combination of artifacts would provide the most comprehensive evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.