
EC-CouncilDigital Forensics Essentials
Domain 3Objective 5
Anti-Forensics Countermeasures DFE Practice Questions (Page 3)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
27questions here
6free pages
7concepts
Questions 11–15
- 11
Which area of a storage device is specifically examined to recover data that may have been hidden in the unused space between the end of a file and the end of the last allocated cluster?
Select an answer first - 12
Which of the following is an essential component of a comprehensive logging and monitoring system for detecting anti-forensics activities?
Select an answer first - 13
A forensic examiner needs to analyze a drive image that contains both encrypted files and hidden data in slack space. The examiner has a limited time window and must prioritize actions to preserve evidence integrity. Which action should the examiner take first?
Select an answer first - 14
Which of the following is a proper evidence handling procedure to ensure the integrity of digital evidence during an investigation?
Select an answer first - 15
You are investigating a case where the suspect used both NTFS alternate data streams (ADS) and steganography to hide data. You have a forensic image of the drive. Which approach should you use to uncover both types of hidden data while maintaining evidence integrity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.