
EC-CouncilDigital Forensics Essentials
Domain 1Objective 2
Digital Evidence and Forensic Readiness DFE Practice Questions (Page 6)
Part of the Computer Forensics Foundations and Process domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
5concepts
Questions 26–30
- 26
An investigator is analyzing a compromised web server. The server's access logs show requests from an IP address that is later found to be a Tor exit node. The investigator also finds a suspicious file in the web root. Which combination of evidence is most probative for identifying the attacker?
Select an answer first - 27
An investigator is examining a suspect's computer and finds a temporary internet file that contains a fragment of a deleted email. Which characteristic of digital evidence does this illustrate?
Select an answer first - 28
A forensic analyst is documenting the chain of custody for a seized hard drive. Which information is essential to include in the documentation?
Select an answer first - 29
During an investigation of a data breach, an analyst finds relevant chat logs on a company server, a suspect's smartphone, and a network firewall's connection logs. Which statement correctly characterizes these sources?
Select an answer first - 30
What is the first step in establishing forensic readiness within an organization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.