
EC-CouncilDigital Forensics Essentials
Domain 4Objective 5
Mac Forensics DFE Practice Questions (Page 2)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 6–10
- 6
A forensic examiner needs to create a forensic image of a Mac's internal SSD that uses APFS. Which tool or method is most appropriate for this task?
Select an answer first - 7
A forensic examiner needs to prove that a file on an APFS volume was downloaded from the internet. Which metadata artifact is most indicative of this?
Select an answer first - 8
An examiner needs to recover the URLs of websites visited by a user in Safari on a Mac running macOS 12 Monterey. The examiner has a forensic image and wants to avoid relying on the user's iCloud history. Which files should the examiner analyze?
Select an answer first - 9
Which tool is commonly used to acquire the contents of a Mac's RAM for forensic analysis?
Select an answer first - 10
Which APFS structure is a point-in-time read-only view of the file system that can be used to recover previous versions of files?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.