
EC-CouncilDigital Forensics Essentials
Domain 1Objective 2
Digital Evidence and Forensic Readiness DFE Practice Questions (Page 3)
Part of the Computer Forensics Foundations and Process domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
5concepts
Questions 11–15
- 11
An investigator needs to prove that a file on a seized computer has not been modified since collection. Which method is most appropriate?
Select an answer first - 12
A company wants to ensure that digital evidence is available for future investigations. Which action is a key component of forensic readiness?
Select an answer first - 13
A company's forensic readiness plan requires that all evidence be preserved for at least two years. However, the legal department says that some data must be deleted after one year due to privacy regulations. How should the company resolve this conflict?
Select an answer first - 14
A system administrator discovers that an employee's workstation has been used to access unauthorized file-sharing sites. The administrator needs to preserve potential evidence while the machine is still running. Which action best supports forensic preservation at this stage?
Select an answer first - 15
Which ethical obligation is most important for a digital forensics examiner?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.