Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 2Objective 2

Boot Processes and File Systems Across Windows, Linux, and macOS DFE Practice Questions (Page 7)

Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.

38questions here
8free pages
7concepts

Questions 31–35

  1. 31expert · hard

    A forensic examiner is analyzing a Windows 10 system that uses BitLocker with a TPM. The examiner has physical access to the system and the recovery key. The system is currently powered off. Which acquisition method will yield a forensically sound image of the decrypted data?

    Select an answer first
  2. 32foundation · easy

    During the Windows boot process, which component is loaded first by the Windows Boot Manager?

    Select an answer first
  3. 33foundation · easy

    In a modern Windows system using UEFI, which component is responsible for initializing hardware and loading the Windows Boot Manager?

    Select an answer first
  4. 34foundation · easy

    Which feature is a key advantage of APFS over HFS+?

    Select an answer first
  5. 35expert · hard

    A Linux system administrator is investigating a server that was compromised. The attacker gained root access and modified the systemd boot configuration to start a malicious service. The administrator needs to determine when the malicious service was added. Which file or command would provide the most reliable evidence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.