Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 3Objective 1

Data Deletion and File Recovery Concepts DFE Practice Questions (Page 4)

Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.

35questions here
7free pages
4concepts

Questions 16–20

  1. 16application · medium

    A forensic analyst is recovering deleted files from a USB drive that was used on both Windows and Linux systems. The drive is formatted with exFAT. Which recovery technique is MOST appropriate?

    Select an answer first
  2. 17application · medium

    An investigator is analyzing a Linux system with an ext4 file system. A file was deleted, and the investigator wants to determine when the file was deleted. Which metadata source is MOST useful?

    Select an answer first
  3. 18application · medium

    A security administrator is preparing a laptop for decommissioning. The requirement is to ensure that sensitive files cannot be recovered using forensic tools. Which approach BEST meets this requirement?

    Select an answer first
  4. 19expert · hard

    A forensic examiner is analyzing a Linux system with ext4. A suspect deleted a file and then created a new file with the same name in the same directory. The examiner wants to recover the original deleted file. What is the most likely outcome?

    Select an answer first
  5. 20foundation · easy

    A forensic examiner needs to recover deleted files from a Windows system. Which approach is most appropriate for recovering files that were logically deleted and whose MFT records are still intact?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.