
EC-CouncilDigital Forensics Essentials
Domain 3Objective 1
Data Deletion and File Recovery Concepts DFE Practice Questions (Page 1)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
35questions here
7free pages
4concepts
Questions 1–5
- 1
A forensic examiner is analyzing a Linux system with ext4. A suspect deleted a file and then ran a script that created a large file to fill the disk. The examiner wants to recover the original deleted file. What is the most likely outcome?
Select an answer first - 2
Which technique is commonly used to recover files from unallocated space when file system metadata is missing or corrupted?
Select an answer first - 3
An investigator is analyzing an ext4 volume from a Linux server. A critical configuration file was deleted three days ago, and the server has been in continuous use since. The investigator wants to recover the file. What is the most significant obstacle to successful recovery?
Select an answer first - 4
An investigator is examining a Linux system with ext4. A file was deleted, and the investigator wants to determine when the file was deleted. Which metadata is most useful for this purpose?
Select an answer first - 5
A forensic analyst is recovering deleted files from a memory card that was used in a digital camera. The card is formatted with FAT32. The analyst finds that the directory entries for the deleted photos are still present, but the cluster chains are not fully intact. What is the BEST approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.