
EC-CouncilDigital Forensics Essentials
Domain 6Objective 1
Dark Web Concepts and Investigation DFE Practice Questions (Page 4)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
47questions here
10free pages
7concepts
Questions 16–20
- 16
A security team is monitoring dark web forums for threats against their organization. They find a post that mentions a specific exploit that could affect their systems. Which action is most appropriate for the team to take?
Select an answer first - 17
A forensic team is investigating a dark web site that hosts illegal content. They have identified a server in a foreign country. What is the most appropriate next step?
Select an answer first - 18
An investigator is tracking a suspect who uses Tor and also runs a public website on the surface web. The investigator suspects the suspect uses the same username on both the dark web and the surface web. Which technique would be most effective in linking the two identities?
Select an answer first - 19
An investigator is considering using a covert technique to identify a dark web user. The technique involves sending a specially crafted image that, when viewed, contacts a server controlled by the investigator, revealing the user's real IP address. What is the primary legal concern with this technique?
Select an answer first - 20
A security analyst is monitoring a dark web forum for mentions of their company's stolen data. The analyst finds a post offering to sell a database that appears to be from their company. Which action should the analyst take to gather intelligence without alerting the seller?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.