
EC-CouncilDigital Forensics Essentials
Domain 4Objective 4
Linux Memory and File System Analysis DFE Practice Questions (Page 6)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
10concepts
Questions 26–30
- 26
Which log file in Linux typically records authentication-related events, such as successful and failed login attempts?
Select an answer first - 27
Which file typically stores the command history for the Bash shell in a user's home directory?
Select an answer first - 28
A forensic analyst is examining a Linux server that was used to launch outbound attacks. The analyst needs to trace the network connections made from this system. Which files and commands should the analyst use to reconstruct the network activity?
Select an answer first - 29
Which directory in Linux contains startup scripts that run when the system boots?
Select an answer first - 30
During a forensic examination of a Linux system, an investigator needs to locate the system's primary log files, user home directories, and temporary files. Which directories should the investigator focus on?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.