
EC-CouncilDigital Forensics Essentials
Domain 1Objective 2
Digital Evidence and Forensic Readiness DFE Practice Questions (Page 9)
Part of the Computer Forensics Foundations and Process domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
5concepts
Questions 41–45
- 41
What is the primary purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 42
An investigator must collect evidence from a server that is still in production and cannot be taken offline. The server hosts a critical application. Which approach best preserves evidence while minimizing disruption?
Select an answer first - 43
A multinational company is designing a forensic readiness program. The legal team requires that all employee communications be logged for potential litigation, but the privacy team warns that this may violate data protection regulations in some countries. The IT team is concerned about the storage cost of logging all communications. Which approach best satisfies all three constraints?
Select an answer first - 44
A forensic team is collecting evidence from a small office network after a suspected data breach. Which source is LEAST likely to contain relevant digital evidence?
Select an answer first - 45
A forensic investigator is asked to collect evidence from a company-owned laptop that is also used for personal activities by the employee. The employee is suspected of fraud. The company's policy states that all data on company devices is company property. Which action is most legally defensible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.