Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 4

Linux Memory and File System Analysis DFE Practice Questions (Page 8)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
10concepts

Questions 36–40

  1. 36expert · hard

    A forensic analyst is examining a Linux system where an attacker deleted several log files and a critical binary. The file system is ext4 and the system was shut down cleanly after the incident. The analyst needs to recover the deleted files and determine the timeline of deletion. Which approach should the analyst take?

    Select an answer first
  2. 37expert · hard

    A security analyst is investigating a Linux server where an attacker gained access via a compromised user account. The analyst needs to determine the exact commands the attacker ran and whether they attempted to escalate privileges. The system has auditd enabled. Which log files should the analyst examine?

    Select an answer first
  3. 38foundation · easy

    Which command displays the current IP address, netmask, and other network interface configuration on a Linux system?

    Select an answer first
  4. 39foundation · easy

    Which command is used to view system log files in real time as new entries are added?

    Select an answer first
  5. 40foundation · easy

    What is a critical best practice when attempting to recover deleted files from a Linux file system?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.