
EC-CouncilDigital Forensics Essentials
Domain 4Objective 4
Linux Memory and File System Analysis DFE Practice Questions (Page 10)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
10concepts
Questions 46–50
- 46
During a forensic investigation of a Linux system, an analyst needs to quickly identify which user accounts were recently added and when the system was last rebooted. Which two files should the analyst examine to gather this information?
Select an answer first - 47
A user accidentally deleted an important document from an ext4 filesystem on a Linux workstation. The investigator needs to recover the file. Which approach is most likely to succeed?
Select an answer first - 48
Which of the following is a dedicated tool specifically designed for capturing volatile memory from a Linux system?
Select an answer first - 49
During a forensic examination, an investigator finds a file with unusual permissions and ownership. The investigator needs to determine if the file was recently modified and by whom. Which combination of commands would provide the most useful information?
Select an answer first - 50
An investigator is analyzing a Linux system that was used to host a web server. The investigator needs to find the web server's configuration files, logs, and any uploaded content. The system uses standard directory conventions. Which directories should be examined?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.