Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 2Objective 2

Boot Processes and File Systems Across Windows, Linux, and macOS DFE Practice Questions (Page 3)

Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.

38questions here
8free pages
7concepts

Questions 11–15

  1. 11expert · hard

    A forensic examiner is analyzing a Mac that runs macOS Monterey (12) with APFS. The examiner needs to determine whether a file was copied from an external drive or created locally. Which APFS feature would be most helpful?

    Select an answer first
  2. 12foundation · easy

    Which Linux file system was the first to introduce journaling, providing faster recovery after a crash?

    Select an answer first
  3. 13application · medium

    A forensic examiner is analyzing a Mac that runs macOS Catalina. The examiner needs to recover deleted files from the internal SSD. Which file system feature should the examiner be aware of?

    Select an answer first
  4. 14application · medium

    A forensic examiner is analyzing a Mac that runs macOS Mojave (10.14) with HFS+ as the boot volume. The examiner needs to recover a deleted file that was stored in a directory that has since been renamed. Which HFS+ feature is most helpful for this task?

    Select an answer first
  5. 15application · medium

    A forensic examiner needs to acquire data from a MacBook Pro that uses FileVault 2 encryption on an APFS volume. The examiner has the user's password. Which method should the examiner use to acquire a forensically sound image?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.