Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 5

Mac Forensics DFE Practice Questions (Page 4)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 16–20

  1. 16application · medium

    During a macOS forensic examination, you need to determine which user accounts were recently added and when they last logged in. Which set of artifacts would provide the most direct evidence?

    Select an answer first
  2. 17application · medium

    An examiner receives a MacBook Pro that was used to download sensitive documents. The system runs macOS 11 Big Sur with FileVault enabled. The examiner needs to acquire the user's Documents folder while preserving metadata. Which acquisition approach is most appropriate?

    Select an answer first
  3. 18foundation · easy

    Which macOS file stores the list of user accounts and their unique identifiers (UIDs)?

    Select an answer first
  4. 19expert · hard

    A forensic examiner is analyzing a Mac and needs to determine if a user accessed a specific website using Safari, but the user has cleared the browsing history. Which alternative artifacts could provide evidence of the website visit?

    Select an answer first
  5. 20application · medium

    An analyst is investigating a Mac where a user may have logged in remotely via SSH. The analyst needs to determine if there were any successful SSH logins. Which artifact should the analyst examine?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.