
EC-CouncilDigital Forensics Essentials
Domain 2Objective 3
File System Analysis and Data Recovery DFE Practice Questions (Page 7)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
41questions here
9free pages
7concepts
Questions 31–35
- 31
In which scenario is data carving most likely to be necessary?
Select an answer first - 32
A forensic examiner has been called to investigate a suspected data theft. The suspect's computer is running, and the examiner needs to preserve evidence. The examiner has a write-blocker and forensic imaging software. What is the first step the examiner should take?
Select an answer first - 33
An investigator is analyzing a Linux system that uses the ext4 file system. The investigator needs to determine when a specific file was last modified, when its metadata was last changed, and when it was last accessed. Which command or tool should the investigator use to view these timestamps?
Select an answer first - 34
In a file system, what is the primary purpose of the file allocation table or inode table?
Select an answer first - 35
A forensic analyst is investigating a case where a suspect deleted a large video file from an NTFS drive. The drive has been used heavily since the deletion. The analyst needs to recover the video. Which approach is most likely to succeed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.