Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 2Objective 1

Disk Drive Types and Logical Structure of a Disk DFE Practice Questions (Page 7)

Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.

34questions here
7free pages
4concepts

Questions 31–34

  1. 31foundation · easy

    Which best practice should be followed when acquiring data from a disk to preserve its evidentiary integrity?

    Select an answer first
  2. 32application · medium

    A forensic examiner is analyzing a disk image from a Windows system that has a single NTFS partition. The examiner needs to determine the size of a file's data on disk, which may be larger than the file's logical size due to slack space. Which structure should the examiner examine to find the file's allocated size?

    Select an answer first
  3. 33expert · hard

    A forensic examiner is analyzing a disk image from a system that uses a RAID 0 array. The examiner needs to recover data from the array. Which of the following is the most important consideration?

    Select an answer first
  4. 34expert · hard

    A forensic examiner is acquiring evidence from a computer that has a hybrid drive (SSHD). The examiner needs to ensure that all data, including data that may have been cached on the SSD portion, is acquired. Which of the following is the most appropriate approach?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to DFE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.