
EC-CouncilDigital Forensics Essentials
Domain 2Objective 2
Boot Processes and File Systems Across Windows, Linux, and macOS DFE Practice Questions (Page 2)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
38questions here
8free pages
7concepts
Questions 6–10
- 6
A forensic investigator is examining a Windows 10 system that was found with the power cord unplugged. The investigator needs to determine whether the system was shut down cleanly or if the power loss was sudden. Which Windows event log entry would be most useful?
Select an answer first - 7
A Mac user reports that their system will not boot and shows a folder with a question mark. The administrator suspects the startup disk is not recognized. Which step should be taken to diagnose the issue?
Select an answer first - 8
A forensic examiner is analyzing a Mac that runs macOS Catalina (10.15) with APFS. The examiner needs to determine when a specific file was last modified. Which APFS feature provides the most reliable timestamp information?
Select an answer first - 9
A forensic investigator is examining a Windows 10 system that has both NTFS and FAT32 partitions. The investigator needs to recover a deleted file from the FAT32 partition. Which characteristic of FAT32 is most relevant to the recovery?
Select an answer first - 10
A forensic investigator is examining a USB flash drive that was used to transfer files between a Windows 10 computer and a macOS computer. The drive is formatted with exFAT. Which characteristic of exFAT is most relevant to the investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.