Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 2Objective 3

File System Analysis and Data Recovery DFE Practice Questions (Page 2)

Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.

41questions here
9free pages
7concepts

Questions 6–10

  1. 6foundation · easy

    In file system analysis, which metadata attribute is most useful for determining when a file was last modified?

    Select an answer first
  2. 7expert · hard

    A forensic examiner is analyzing a disk image from a system that used a file system with journaling. The examiner needs to recover a file that was deleted just before the system crashed. Which technique is most likely to recover the file's content?

    Select an answer first
  3. 8application · medium

    A forensic examiner is analyzing a disk image from a system that used a proprietary file system. The file system metadata is not recognized by the examiner's tools. The examiner needs to recover documents that were deleted. Which approach is most appropriate?

    Select an answer first
  4. 9expert · hard

    A forensic examiner is recovering files from a disk image. The examiner knows that some files are fragmented. Which data carving technique is most appropriate to recover fragmented files?

    Select an answer first
  5. 10foundation · easy

    When a file is deleted in a typical file system, what happens to the file's data blocks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.