Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 4

Linux Memory and File System Analysis DFE Practice Questions (Page 2)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
10concepts

Questions 6–10

  1. 6application · easy

    An analyst is investigating a Linux server that may have been used to scan internal networks. The analyst needs to determine the network interfaces and IP addresses configured on the system at the time of the incident. Which command or file would provide this information?

    Select an answer first
  2. 7application · medium

    An investigator is examining a Linux system that may have a persistence mechanism. The investigator needs to identify services that start automatically at boot. Which directories or files should be checked?

    Select an answer first
  3. 8foundation · easy

    In Linux file system metadata, which timestamp represents the last time the file's content was modified?

    Select an answer first
  4. 9foundation · easy

    Which Linux command is commonly used to recover deleted files from an ext4 file system?

    Select an answer first
  5. 10foundation · easy

    In the Linux file system hierarchy, which directory typically contains system configuration files?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.