
EC-CouncilDigital Forensics Essentials
Domain 3Objective 4
Artifact Wiping and Trail Obfuscation DFE Practice Questions (Page 7)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
34questions here
7free pages
3concepts
Questions 31–34
- 31
A security team is investigating a compromised Linux server. The attacker deleted the /var/log/auth.log and cleared the bash history. However, the team finds that the system was configured with auditd and the audit logs are stored in /var/log/audit/audit.log. The attacker also attempted to delete the audit.log but failed because the file was immutable (chattr +i). Which of the following is the most reliable source of evidence?
Select an answer first - 32
A forensic examiner is investigating a suspect who used a disk-wiping tool to erase the entire hard drive. The examiner has a forensic image of the drive taken after the wiping. The examiner notices that the first few sectors of the drive contain a pattern that is not typical of a wiped drive. Which conclusion is most appropriate?
Select an answer first - 33
A forensic investigator is examining a Windows system where the user has cleared the Prefetch files and the UserAssist registry key. The investigator wants to determine which applications were executed. Which of the following artifacts would be most useful?
Select an answer first - 34
An administrator notices that the Windows Event Logs on a critical server have been cleared, and the system time was changed back by two hours during the same period. The administrator suspects an attacker is trying to hide their activities. Which anti-forensic technique is being used, and what should the administrator do to preserve evidence?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.