
EC-CouncilDigital Forensics Essentials
Domain 2Objective 3
File System Analysis and Data Recovery DFE Practice Questions (Page 1)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
41questions here
9free pages
7concepts
Questions 1–5
- 1
A user accidentally deleted a critical spreadsheet from an NTFS-formatted external drive. The drive has been used minimally since the deletion. The user wants to recover the file. Which recovery method is most likely to succeed?
Select an answer first - 2
A forensic examiner is analyzing a Linux system that uses ext4. The examiner needs to determine the exact time a file was deleted. The file system has been mounted and used since the deletion. Which source of metadata is most likely to provide the deletion time?
Select an answer first - 3
Which technique is commonly used to recover a deleted file when the file system metadata is still available?
Select an answer first - 4
A forensic examiner is working on a case where the evidence drive is a solid-state drive (SSD) that supports TRIM. The examiner needs to recover deleted files. The SSD has been in use for several weeks since the deletion. What is the most important consideration?
Select an answer first - 5
A forensic examiner is about to analyze a hard drive that is part of a legal case. The examiner needs to ensure that the evidence is preserved and that the chain of custody is maintained. Which action is most important to take before starting the analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.