Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 2Objective 3

File System Analysis and Data Recovery DFE Practice Questions (Page 5)

Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.

41questions here
9free pages
7concepts

Questions 21–25

  1. 21expert · medium

    A forensic analyst is using Autopsy to analyze a disk image. The analyst needs to recover deleted files and also create a timeline of file activity. Which Autopsy feature should the analyst use?

    Select an answer first
  2. 22application · medium

    An investigator has a forensic image of a memory card from a digital camera. The file system is corrupted and the directory entries are unreadable. The investigator needs to recover as many JPEG photos as possible. Which technique is most appropriate?

    Select an answer first
  3. 23application · medium

    A forensic examiner is about to recover deleted files from a suspect's hard drive. The drive is currently in a forensic workstation. Which step should the examiner take FIRST to preserve evidence?

    Select an answer first
  4. 24foundation · easy

    Which open-source tool is commonly used to recover deleted files from a forensic image by analyzing file system structures?

    Select an answer first
  5. 25application · medium

    A forensic examiner is comparing two file systems: FAT32 and NTFS. The examiner needs to recover a deleted file that was stored in a directory with many files. Which file system is more likely to allow recovery of the file's original name and directory structure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.