
EC-CouncilDigital Forensics Essentials
Domain 2Objective 1
Disk Drive Types and Logical Structure of a Disk DFE Practice Questions (Page 5)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
34questions here
7free pages
4concepts
Questions 21–25
- 21
A forensic examiner must acquire a laptop that has a 256 GB SSD with hardware-based full-disk encryption (FDE) enabled. The laptop is powered off, and the examiner does not have the password. The examiner needs to acquire the data for analysis. Which approach is most likely to yield usable evidence?
Select an answer first - 22
A forensic examiner is analyzing a disk image from a Linux system. The image contains a partition formatted with ext4. The examiner needs to determine the block size of the file system. Which structure should the examiner examine?
Select an answer first - 23
A forensic analyst is comparing the logical structure of a traditional HDD and an SSD. The analyst needs to explain to a colleague why the concept of 'cylinders' is less relevant for SSDs. Which statement is accurate?
Select an answer first - 24
A forensic team must acquire the internal SSD of a laptop that was used to send threatening emails. The SSD supports the TRIM command and has been in use for several months. The team needs to maximize the chance of recovering deleted email fragments. Which acquisition strategy is most appropriate?
Select an answer first - 25
Which file system is commonly used by modern Linux distributions as the default native file system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.