
EC-CouncilDigital Forensics Essentials
Domain 1Objective 2
Digital Evidence and Forensic Readiness DFE Practice Questions (Page 7)
Part of the Computer Forensics Foundations and Process domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
5concepts
Questions 31–35
- 31
An investigator collects a laptop from a suspect's desk. The laptop is powered on and shows an open email client. To preserve evidence, which action should the investigator take first?
Select an answer first - 32
Which of the following is a common source of digital evidence?
Select an answer first - 33
During an investigation, an examiner discovers that the evidence includes private emails between employees. The examiner is not authorized to view personal communications. What should the examiner do?
Select an answer first - 34
An investigator is collecting evidence from a corporate network. Which source is most likely to contain evidence of an employee's web browsing activity?
Select an answer first - 35
An investigator is collecting evidence from a network after a data exfiltration incident. The network has a firewall, an intrusion detection system (IDS), and a proxy server. The investigator needs to determine what data was exfiltrated. Which source is most likely to contain the actual data that was sent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.