Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 4

Linux Memory and File System Analysis DFE Practice Questions (Page 7)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
10concepts

Questions 31–35

  1. 31foundation · easy

    Where are password hashes for user accounts stored on modern Linux systems?

    Select an answer first
  2. 32foundation · easy

    Which command is commonly used to capture the contents of physical memory (RAM) from a Linux system for forensic analysis?

    Select an answer first
  3. 33foundation · easy

    Which command is used to display active network connections, listening ports, and routing tables on a Linux system?

    Select an answer first
  4. 34expert · hard

    An analyst is investigating a Linux server that was compromised. The attacker installed a rootkit that hides processes and network connections. The analyst needs to identify the rootkit and understand its persistence mechanism. Which approach should the analyst take?

    Select an answer first
  5. 35application · medium

    An analyst is investigating a Linux system where an attacker used the command line to perform malicious actions. The analyst needs to reconstruct the exact commands the attacker executed. Which sources should the analyst examine to recover this information?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.