
EC-CouncilDigital Forensics Essentials
Domain 3Objective 4
Artifact Wiping and Trail Obfuscation DFE Practice Questions (Page 4)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
34questions here
7free pages
3concepts
Questions 16–20
- 16
A forensic examiner is investigating a suspect's SSD. The suspect used a wiping tool that overwrites free space with zeros. However, the examiner finds that some deleted files are still recoverable. Which of the following is the most likely reason?
Select an answer first - 17
A user is suspected of using a secure deletion tool to wipe individual files. The forensic examiner finds that the files' MFT entries are gone, but the clusters that contained the data show patterns of multiple overwrites. Which conclusion is most appropriate?
Select an answer first - 18
During an investigation, an examiner finds that a suspect used a tool to wipe the unallocated space on a hard drive. The examiner also notices that the partition table has been modified to hide a small partition. Which countermeasure is most effective for detecting the hidden partition?
Select an answer first - 19
What is the goal of log manipulation as a trail obfuscation technique?
Select an answer first - 20
Which method is commonly used to wipe storage media to prevent data recovery?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.