Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 4

Linux Memory and File System Analysis DFE Practice Questions (Page 3)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
10concepts

Questions 11–15

  1. 11expert · hard

    A forensic analyst is investigating a Linux system where an attacker deleted a database file. The file system is ext4 and the partition has been unmounted. The analyst needs to recover the file and determine when it was deleted. Which approach should the analyst take?

    Select an answer first
  2. 12application · medium

    An analyst is investigating a Linux system that was compromised. The attacker may have installed a persistent backdoor that starts on boot. Which files should the analyst examine to identify this persistence mechanism?

    Select an answer first
  3. 13expert · hard

    An analyst has a memory dump from a Linux server and needs to determine if a specific process was communicating with an external IP address. The analyst has the Volatility profile for the system. Which set of Volatility commands would provide the most direct evidence?

    Select an answer first
  4. 14expert · medium

    An investigator is analyzing a Linux system that may have a rootkit. The investigator needs to identify any suspicious processes and services that are running. Which combination of commands would provide the most comprehensive view?

    Select an answer first
  5. 15expert · hard

    An analyst has a memory dump from a compromised Linux server. The analyst needs to determine if the attacker used a specific exploit tool and what network connections were active. The analyst also needs to identify any processes that were hidden from the operating system. Which Volatility plugins should the analyst use in combination?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.