
EC-CouncilDigital Forensics Essentials
Domain 4Objective 4
Linux Memory and File System Analysis DFE Practice Questions (Page 4)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
10concepts
Questions 16–20
- 16
A forensic examiner is reconstructing the actions of a user on a Linux system. The user's `.bash_history` file has been cleared. The examiner needs to find other sources of command history. Which approach is most likely to yield useful evidence?
Select an answer first - 17
An analyst is examining a Linux file system image and needs to determine when a specific file was last accessed, modified, and when its metadata was last changed. The analyst also needs to identify the file's original owner. Which command should the analyst use to gather all this information?
Select an answer first - 18
A forensic analyst is examining a Linux file system image and needs to determine the exact timeline of when a file was created, modified, and accessed. The file system is ext4 and the analyst has a raw image. Which tool should the analyst use to extract the most accurate timeline information?
Select an answer first - 19
A security analyst is reviewing a Linux server's logs after a suspected brute-force attack on SSH. The analyst needs to identify the source IP addresses that attempted authentication and whether any succeeded. Which log file and command should the analyst use?
Select an answer first - 20
An investigator is examining a file on a Linux filesystem and needs to determine when the file's content was last modified, when its metadata was last changed, and when it was last accessed. Which command provides all three timestamps?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.