
EC-CouncilDigital Forensics Essentials
Domain 3Objective 1
Data Deletion and File Recovery Concepts DFE Practice Questions (Page 6)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
35questions here
7free pages
4concepts
Questions 26–30
- 26
A system administrator is preparing a decommissioned laptop for disposal. The laptop has an SSD with TRIM enabled. The administrator wants to ensure that sensitive files are unrecoverable. Which action is most effective?
Select an answer first - 27
A forensic examiner is trying to recover a deleted JPEG image from a USB drive formatted with FAT32. The file was fragmented across three non-contiguous clusters. Which recovery method is most likely to succeed?
Select an answer first - 28
A user reports that a sensitive spreadsheet was accidentally deleted from an NTFS volume on a Windows 10 workstation. The user immediately shut down the machine after realizing the mistake. A forensic examiner needs to recover the file. The examiner boots the system from a forensic USB drive and begins analysis. Which approach is most likely to recover the spreadsheet content?
Select an answer first - 29
A forensic examiner is investigating a case where a suspect deleted a critical PDF file from an NTFS volume. The examiner has a full disk image. The file was stored in a fragmented manner across the disk. The examiner has identified the MFT entry, but the data runs are incomplete. What is the most effective approach to recover the PDF?
Select an answer first - 30
In a Unix-like file system using inodes, what happens to the inode when a file is deleted?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.