
EC-CouncilDigital Forensics Essentials
Domain 2Objective 2
Boot Processes and File Systems Across Windows, Linux, and macOS DFE Practice Questions (Page 7)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
38questions here
8free pages
7concepts
Questions 31–35
- 31
A forensic examiner is analyzing a Windows 10 system that uses BitLocker with a TPM. The examiner has physical access to the system and the recovery key. The system is currently powered off. Which acquisition method will yield a forensically sound image of the decrypted data?
Select an answer first - 32
During the Windows boot process, which component is loaded first by the Windows Boot Manager?
Select an answer first - 33
In a modern Windows system using UEFI, which component is responsible for initializing hardware and loading the Windows Boot Manager?
Select an answer first - 34
Which feature is a key advantage of APFS over HFS+?
Select an answer first - 35
A Linux system administrator is investigating a server that was compromised. The attacker gained root access and modified the systemd boot configuration to start a malicious service. The administrator needs to determine when the malicious service was added. Which file or command would provide the most reliable evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.