
EC-CouncilDigital Forensics Essentials
Domain 4Objective 4
Linux Memory and File System Analysis DFE Practice Questions (Page 1)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
10concepts
Questions 1–5
- 1
Which command is used to list currently running processes on a Linux system?
Select an answer first - 2
Which tool is commonly used to analyze a Linux memory dump to list running processes?
Select an answer first - 3
A forensic analyst responds to a suspected network intrusion on a Linux database server. The system is still running, and the analyst must preserve volatile data before shutting down the server for imaging. The analyst has root access and a USB drive mounted at /mnt/evidence. Which action should the analyst take FIRST to capture the most volatile data in a forensically sound manner?
Select an answer first - 4
Which command can be used to display the current session's command history in Bash?
Select an answer first - 5
Which file in Linux contains user account information such as usernames, UIDs, and home directories?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.