
EC-CouncilDigital Forensics Essentials
Domain 2Objective 5
Forensic Image Formats and Standards DFE Practice Questions (Page 1)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
22questions here
5free pages
4concepts
Questions 1–5
- 1
Which forensic image format is defined by a specification that includes a header with fields for case number, evidence number, and examiner name, and is commonly associated with EnCase?
Select an answer first - 2
A forensic examiner needs to acquire a large server drive. The acquisition must be completed quickly, and the examiner has ample storage space. The examiner does not need compression or metadata. Which image format should the examiner use to maximize acquisition speed?
Select an answer first - 3
A small forensic lab receives evidence drives from various law enforcement agencies. The lab uses open-source tools and occasionally needs to share images with agencies that use commercial software. The lab wants a format that is open, supports compression, and is readable by both open-source and commercial tools. Which format best meets these needs?
Select an answer first - 4
Which forensic image format is essentially a raw bit-for-bit copy of a storage device, often created with tools like `dd` or `dcfldd`, and does not include built-in metadata or compression?
Select an answer first - 5
A forensic lab is deciding between E01 and AFF for a new case. The lab needs to store the image on a network share that has a file size limit of 2 GB per file. The lab also needs to preserve the ability to add custom metadata during acquisition. Which format should the lab choose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.