Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 5

Mac Forensics DFE Practice Questions (Page 2)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 6–10

  1. 6application · medium

    A forensic examiner needs to create a forensic image of a Mac's internal SSD that uses APFS. Which tool or method is most appropriate for this task?

    Select an answer first
  2. 7application · easy

    A forensic examiner needs to prove that a file on an APFS volume was downloaded from the internet. Which metadata artifact is most indicative of this?

    Select an answer first
  3. 8application · medium

    An examiner needs to recover the URLs of websites visited by a user in Safari on a Mac running macOS 12 Monterey. The examiner has a forensic image and wants to avoid relying on the user's iCloud history. Which files should the examiner analyze?

    Select an answer first
  4. 9foundation · easy

    Which tool is commonly used to acquire the contents of a Mac's RAM for forensic analysis?

    Select an answer first
  5. 10foundation · easy

    Which APFS structure is a point-in-time read-only view of the file system that can be used to recover previous versions of files?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.