
EC-CouncilDigital Forensics Essentials
Domain 3Objective 5
Anti-Forensics Countermeasures DFE Practice Questions (Page 4)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
27questions here
6free pages
7concepts
Questions 16–20
- 16
A forensic investigator encounters a laptop with BitLocker-encrypted drives. The suspect is known to have used the laptop recently, but it is now powered off. Which approach should the investigator take to access the encrypted data?
Select an answer first - 17
Which forensic technique is used to recover residual data from storage media after an anti-forensics attempt to wipe or overwrite files?
Select an answer first - 18
An organization suspects that an employee used a disk wiping tool to destroy evidence of data exfiltration. The IT team has a forensic image of the drive, but the image was taken after the wiping occurred. Which analysis technique is most likely to reveal evidence of the exfiltration?
Select an answer first - 19
What is the primary purpose of using write blockers during forensic evidence acquisition?
Select an answer first - 20
A forensic examiner is investigating a case where the suspect used multiple anti-forensics techniques, including data hiding, artifact wiping, and encryption. The examiner has a forensic image of the drive. Which combination of techniques should the examiner use to maximize the recovery of evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.