
EC-CouncilDigital Forensics Essentials
Domain 1Objective 2
Digital Evidence and Forensic Readiness DFE Practice Questions (Page 8)
Part of the Computer Forensics Foundations and Process domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
5concepts
Questions 36–40
- 36
A financial services company wants to improve its ability to respond to insider-threat incidents. The legal team has approved a policy that requires logging of all employee file-access activity, but the operations team is concerned about the storage cost of keeping logs for the required retention period. Which approach best balances forensic readiness with operational constraints?
Select an answer first - 37
A forensic investigator is collecting evidence from a cloud-hosted server. Which legal consideration is most important to address before collection?
Select an answer first - 38
An investigator is collecting evidence from a crime scene and finds a smartphone, a USB drive, and a router. Which item requires special handling to preserve volatile data?
Select an answer first - 39
An investigator is documenting evidence from a computer and notices that the system clock is incorrect. Why is this significant?
Select an answer first - 40
A forensic examiner needs to document who accessed a seized hard drive and when. Which practice best supports the chain of custody?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.