Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 5

Mac Forensics DFE Practice Questions (Page 5)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 21–25

  1. 21application · medium

    You are examining a Mac that experienced an unexpected shutdown. You need to determine whether the shutdown was caused by a user action or a system failure. Which log or artifact would you examine first?

    Select an answer first
  2. 22application · medium

    An analyst is investigating a Mac where a user allegedly accessed a specific website and downloaded a file. Which combination of artifacts would provide the strongest evidence of this activity?

    Select an answer first
  3. 23application · medium

    During a Mac investigation, you need to analyze a memory dump from a suspect's Mac. Which tool is specifically designed for Mac memory analysis?

    Select an answer first
  4. 24foundation · easy

    Which macOS logging system collects and stores log messages from all system components in a unified, searchable format?

    Select an answer first
  5. 25application · medium

    An examiner is analyzing a file on an APFS volume and needs to determine if the file was downloaded from the internet. Which metadata attribute should the examiner check?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.