
EC-CouncilDigital Forensics Essentials
Domain 1Objective 2
Digital Evidence and Forensic Readiness DFE Practice Questions (Page 1)
Part of the Computer Forensics Foundations and Process domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
5concepts
Questions 1–5
- 1
An investigator is documenting evidence from a network intrusion. Which item is considered digital evidence?
Select an answer first - 2
A forensic investigator is examining a USB drive found at a crime scene. Which characteristic of the data on the USB drive makes it digital evidence?
Select an answer first - 3
An investigator is examining a smartphone seized from a suspect. Which type of data is considered volatile and may be lost if the device is powered off?
Select an answer first - 4
A multinational company must comply with data protection laws that require personal data to be stored in specific countries. Their forensic readiness plan involves collecting evidence from servers in multiple regions. What is the primary legal consideration?
Select an answer first - 5
In the context of a forensic investigation, which statement best defines digital evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.