
EC-CouncilDigital Forensics Essentials
Domain 3Objective 1
Data Deletion and File Recovery Concepts DFE Practice Questions (Page 7)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
35questions here
7free pages
4concepts
Questions 31–35
- 31
An investigator is examining an NTFS volume and finds that the MFT entry for a deleted file is still present, but the file's data runs are marked as unallocated. What does this indicate about the deletion and the recovery potential?
Select an answer first - 32
A user deleted a file from a USB drive and then immediately removed the drive. The drive is now being analyzed. The file system is FAT32. What is the most likely state of the file's data?
Select an answer first - 33
A user reports that they accidentally deleted a folder containing multiple files from a network share. The share is hosted on a Windows Server with NTFS. The user did not use the Recycle Bin because the share is configured to bypass it. What is the BEST first step for the administrator to attempt recovery?
Select an answer first - 34
A forensic examiner is analyzing a USB drive formatted with FAT32. A user deleted a file and then ran a disk check utility (CHKDSK) on the drive. The examiner wants to recover the deleted file. What is the most likely impact of the CHKDSK on the recovery?
Select an answer first - 35
A forensic examiner is analyzing a Windows system with NTFS. A file was deleted, and the examiner wants to recover it. The examiner notices that the file was stored in a single contiguous run on the disk. What is the most likely outcome of the recovery attempt?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.