
EC-CouncilDigital Forensics Essentials
Domain 4Objective 5
Mac Forensics DFE Practice Questions (Page 4)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 16–20
- 16
During a macOS forensic examination, you need to determine which user accounts were recently added and when they last logged in. Which set of artifacts would provide the most direct evidence?
Select an answer first - 17
An examiner receives a MacBook Pro that was used to download sensitive documents. The system runs macOS 11 Big Sur with FileVault enabled. The examiner needs to acquire the user's Documents folder while preserving metadata. Which acquisition approach is most appropriate?
Select an answer first - 18
Which macOS file stores the list of user accounts and their unique identifiers (UIDs)?
Select an answer first - 19
A forensic examiner is analyzing a Mac and needs to determine if a user accessed a specific website using Safari, but the user has cleared the browsing history. Which alternative artifacts could provide evidence of the website visit?
Select an answer first - 20
An analyst is investigating a Mac where a user may have logged in remotely via SSH. The analyst needs to determine if there were any successful SSH logins. Which artifact should the analyst examine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.