
EC-CouncilDigital Forensics Essentials
Domain 2Objective 2
Boot Processes and File Systems Across Windows, Linux, and macOS DFE Practice Questions (Page 5)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
38questions here
8free pages
7concepts
Questions 21–25
- 21
A Linux administrator is setting up a new server and must choose a file system for the root partition. The server will host a database that requires high reliability and supports snapshots. Which file system should the administrator choose?
Select an answer first - 22
A forensic investigator is examining a Windows 10 system that has a dual-boot configuration with Linux. The investigator needs to determine which operating system was used last. Which evidence would be most reliable?
Select an answer first - 23
A forensic examiner receives a Windows 10 laptop that will not boot. The examiner needs to acquire the evidence without altering the system. The examiner decides to remove the hard drive and connect it to a write-blocker on a forensic workstation. The drive contains a BitLocker-encrypted NTFS volume. Which approach should the examiner take to access the encrypted data?
Select an answer first - 24
A forensic examiner needs to recover deleted files from a Mac that runs macOS Catalina (10.15) with APFS. The user had enabled FileVault. Which statement correctly describes the challenge and the appropriate approach?
Select an answer first - 25
Which feature is unique to NTFS among the listed Windows file systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.