
EC-CouncilDigital Forensics Essentials
Domain 2Objective 1
Disk Drive Types and Logical Structure of a Disk DFE Practice Questions (Page 4)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
34questions here
7free pages
4concepts
Questions 16–20
- 16
A forensic examiner is acquiring evidence from a computer that has been running for several days. The examiner needs to capture the system's volatile memory as well as the disk. Which of the following is the most important consideration when performing a live acquisition?
Select an answer first - 17
A forensic examiner must acquire a laptop that has a 512 GB NVMe SSD. The laptop is running Windows 10 with BitLocker enabled. The examiner has the BitLocker recovery key. The laptop is currently powered on and the user is logged in. The examiner wants to create a forensic image that includes the unallocated space. Which approach is most appropriate?
Select an answer first - 18
A forensic examiner is acquiring evidence from a laptop that has an SSD. The examiner is concerned about the TRIM command and its effect on deleted data. Which of the following is the most accurate statement regarding TRIM and forensic acquisition?
Select an answer first - 19
Why is it important for a forensic examiner to know whether a suspect drive is an SSD or an HDD before performing data acquisition?
Select an answer first - 20
In the logical structure of a disk, what is a cluster?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.