
EC-CouncilDigital Forensics Essentials
Domain 2Objective 1
Disk Drive Types and Logical Structure of a Disk DFE Practice Questions (Page 3)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
34questions here
7free pages
4concepts
Questions 11–15
- 11
A forensic examiner is examining a USB flash drive that was found at a crime scene. The drive is formatted with FAT32. The examiner needs to recover a deleted file. Which aspect of FAT32 is most relevant to the recovery?
Select an answer first - 12
A forensic examiner is preparing to analyze a disk image from a Linux server that uses ext4. The examiner needs to identify the file system's block size and the location of the superblock. Which of the following tools or commands would be most appropriate?
Select an answer first - 13
A forensic lab receives a computer that was used to download illegal content. The computer has a solid-state drive (SSD). The examiner needs to acquire the drive. Which consideration is most important when acquiring an SSD compared to an HDD?
Select an answer first - 14
A forensic examiner is asked to acquire evidence from a computer that has a hybrid drive (SSHD). The examiner needs to ensure that all data, including data that may have been cached on the SSD portion, is acquired. Which of the following is the most important consideration?
Select an answer first - 15
A forensic examiner is analyzing a disk image from a Linux system that uses ext4. The examiner needs to find the location of a specific file's data on the disk. Which structure should the examiner consult to find the file's data blocks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.