
EC-CouncilDigital Forensics Essentials
Domain 2Objective 2
Boot Processes and File Systems Across Windows, Linux, and macOS DFE Practice Questions (Page 3)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
38questions here
8free pages
7concepts
Questions 11–15
- 11
A forensic examiner is analyzing a Mac that runs macOS Monterey (12) with APFS. The examiner needs to determine whether a file was copied from an external drive or created locally. Which APFS feature would be most helpful?
Select an answer first - 12
Which Linux file system was the first to introduce journaling, providing faster recovery after a crash?
Select an answer first - 13
A forensic examiner is analyzing a Mac that runs macOS Catalina. The examiner needs to recover deleted files from the internal SSD. Which file system feature should the examiner be aware of?
Select an answer first - 14
A forensic examiner is analyzing a Mac that runs macOS Mojave (10.14) with HFS+ as the boot volume. The examiner needs to recover a deleted file that was stored in a directory that has since been renamed. Which HFS+ feature is most helpful for this task?
Select an answer first - 15
A forensic examiner needs to acquire data from a MacBook Pro that uses FileVault 2 encryption on an APFS volume. The examiner has the user's password. Which method should the examiner use to acquire a forensically sound image?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.