
EC-CouncilDigital Forensics Essentials
Domain 3Objective 1
Data Deletion and File Recovery Concepts DFE Practice Questions (Page 4)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
35questions here
7free pages
4concepts
Questions 16–20
- 16
A forensic analyst is recovering deleted files from a USB drive that was used on both Windows and Linux systems. The drive is formatted with exFAT. Which recovery technique is MOST appropriate?
Select an answer first - 17
An investigator is analyzing a Linux system with an ext4 file system. A file was deleted, and the investigator wants to determine when the file was deleted. Which metadata source is MOST useful?
Select an answer first - 18
A security administrator is preparing a laptop for decommissioning. The requirement is to ensure that sensitive files cannot be recovered using forensic tools. Which approach BEST meets this requirement?
Select an answer first - 19
A forensic examiner is analyzing a Linux system with ext4. A suspect deleted a file and then created a new file with the same name in the same directory. The examiner wants to recover the original deleted file. What is the most likely outcome?
Select an answer first - 20
A forensic examiner needs to recover deleted files from a Windows system. Which approach is most appropriate for recovering files that were logically deleted and whose MFT records are still intact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.