
EC-CouncilDigital Forensics Essentials
Domain 3Objective 4
Artifact Wiping and Trail Obfuscation DFE Practice Questions (Page 6)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
34questions here
7free pages
3concepts
Questions 26–30
- 26
Which technique is an example of trail obfuscation?
Select an answer first - 27
A forensic examiner is analyzing a suspect's laptop and finds that the $MFT has been partially overwritten, and the $LogFile has been cleared. The examiner also notices that the Last Modified timestamps of several files have been changed to a date in the future. Which combination of anti-forensic techniques is indicated, and what is the most important countermeasure?
Select an answer first - 28
Which strategy is used to detect artifact wiping attempts during an investigation?
Select an answer first - 29
A forensic team is investigating a data breach. The attacker wiped the Windows Event Logs and deleted the $MFT entries for the malicious executable. However, the team finds that the Volume Shadow Copies (VSS) still contain an older version of the event logs. Which countermeasure would be most effective to preserve this evidence?
Select an answer first - 30
A forensic examiner is analyzing a seized laptop from a terminated employee. The examiner notices that the NTFS $LogFile and $UsnJrnl are unusually small and contain no entries for the last two weeks, even though the user was active. The user had administrative rights and had installed a 'privacy cleaner' tool. Which action by the user most directly explains the missing journal entries?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.