Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 5

Mac Forensics DFE Practice Questions (Page 1)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 1–5

  1. 1expert · hard

    A forensic examiner is asked to recover deleted files from an APFS volume. The Mac was used for several weeks after deletion. Which factor most significantly impacts the likelihood of recovery?

    Select an answer first
  2. 2application · medium

    A forensic analyst needs to capture the contents of RAM from a running Mac without altering the system. Which method should the analyst use?

    Select an answer first
  3. 3expert · hard

    An examiner is analyzing an APFS volume and notices that a file's modification timestamp is earlier than its creation timestamp. What is the most plausible explanation?

    Select an answer first
  4. 4expert · medium

    An examiner is investigating a Mac where a user allegedly accessed a classified document. The user claims they never logged in during the time of access. Which artifact would most likely disprove this claim?

    Select an answer first
  5. 5foundation · easy

    Which macOS file contains the contents of RAM when the system enters hibernation mode?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.