Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 3Objective 5

Anti-Forensics Countermeasures DFE Practice Questions (Page 3)

Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.

27questions here
6free pages
7concepts

Questions 11–15

  1. 11foundation · easy

    Which area of a storage device is specifically examined to recover data that may have been hidden in the unused space between the end of a file and the end of the last allocated cluster?

    Select an answer first
  2. 12foundation · easy

    Which of the following is an essential component of a comprehensive logging and monitoring system for detecting anti-forensics activities?

    Select an answer first
  3. 13expert · hard

    A forensic examiner needs to analyze a drive image that contains both encrypted files and hidden data in slack space. The examiner has a limited time window and must prioritize actions to preserve evidence integrity. Which action should the examiner take first?

    Select an answer first
  4. 14foundation · easy

    Which of the following is a proper evidence handling procedure to ensure the integrity of digital evidence during an investigation?

    Select an answer first
  5. 15expert · hard

    You are investigating a case where the suspect used both NTFS alternate data streams (ADS) and steganography to hide data. You have a forensic image of the drive. Which approach should you use to uncover both types of hidden data while maintaining evidence integrity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.