
EC-CouncilDigital Forensics Essentials
Domain 1Objective 2
Digital Evidence and Forensic Readiness DFE Practice Questions (Page 5)
Part of the Computer Forensics Foundations and Process domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
5concepts
Questions 21–25
- 21
A company's forensic readiness plan requires that all evidence be collected and preserved within 24 hours of an incident. However, the only trained investigator is on vacation, and the IT team has no forensic training. The company has a legal obligation to preserve evidence. Which action is most appropriate?
Select an answer first - 22
A forensic analyst is asked to determine whether a file was downloaded from the internet. Which type of digital evidence would be most useful?
Select an answer first - 23
A mid-sized company wants to establish forensic readiness without hiring a full-time forensic investigator. Which step is most effective as a starting point?
Select an answer first - 24
A forensic investigator is called to a crime scene where a suspect's laptop is found open and logged in. The investigator needs to collect evidence without altering it. Which action is most appropriate for preserving the integrity of the evidence?
Select an answer first - 25
A forensic team is preparing to collect evidence from a server that has been compromised. The team has a write-blocker and imaging software. Which step should be performed FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.