Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 2Objective 3

File System Analysis and Data Recovery DFE Practice Questions (Page 8)

Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.

41questions here
9free pages
7concepts

Questions 36–40

  1. 36expert · hard

    A forensic examiner is trying to recover a deleted file from an NTFS volume. The file was large and fragmented. The examiner has identified the file's $MFT record, but the data runs are not contiguous. Which technique is most likely to recover the file's content?

    Select an answer first
  2. 37application · medium

    A user deleted a file from a USB drive formatted with FAT32. The drive has been used to store other files since the deletion. The user wants to recover the original file. Which factor most affects the likelihood of successful recovery?

    Select an answer first
  3. 38expert · hard

    An organization is choosing a file system for a new forensic analysis workstation. The workstation will be used to analyze evidence from various sources. Which file system feature is most important for forensic analysis?

    Select an answer first
  4. 39application · medium

    A forensic analyst is using The Sleuth Kit (TSK) to analyze a disk image. The analyst wants to recover deleted files from an NTFS partition. Which TSK tool should the analyst use to list deleted files?

    Select an answer first
  5. 40foundation · easy

    What is the primary purpose of creating a forensic image of a storage device before performing data recovery?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.