Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 3Objective 4

Artifact Wiping and Trail Obfuscation DFE Practice Questions (Page 5)

Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.

34questions here
7free pages
3concepts

Questions 21–25

  1. 21expert · hard

    A forensic examiner is investigating a case where the suspect used a tool to manipulate the Windows Event Logs to remove specific entries. The examiner has a forensic image of the system, but the image was taken after the manipulation. Which approach is most likely to reveal the removed log entries?

    Select an answer first
  2. 22application · medium

    A forensic examiner is analyzing a suspect's laptop. The examiner notices that the NTFS $LogFile and $UsnJrnl entries for a specific time window are missing, and the system's event logs show a gap during the same period. The suspect's user profile contains a folder named 'sysbackup' with hundreds of small text files that appear to be fragments of deleted files. Which anti-forensic technique is most likely being used?

    Select an answer first
  3. 23expert · hard

    A security analyst is investigating a data exfiltration incident. The attacker used steganography to hide data in image files and also altered the file timestamps to make them appear old. The analyst finds that the image files are stored on a network share with file auditing enabled. Which of the following would be the most effective way to determine when the files were actually accessed?

    Select an answer first
  4. 24application · medium

    A forensic examiner is investigating a case of intellectual property theft. The suspect's computer has a Linux OS, and the examiner finds that the bash history file is empty, but the system's syslog shows no gaps. The suspect had installed a tool that claims to 'clean' shell history. Which of the following would be the most reliable way to recover the deleted bash history?

    Select an answer first
  5. 25application · medium

    A security analyst is investigating a compromised server. The attacker deleted the auth.log file and cleared the bash history. However, the analyst finds that the system's audit daemon (auditd) was configured to send logs to a remote syslog server. Which countermeasure would be most effective to recover the attacker's actions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.