Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 5

Mac Forensics DFE Practice Questions (Page 6)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 26–30

  1. 26foundation · easy

    Which macOS log file records authentication events, such as successful and failed login attempts?

    Select an answer first
  2. 27expert · hard

    A Mac was found powered off, and the examiner needs to recover the contents of an encrypted messaging app that was running before shutdown. Which approach is most likely to yield useful data?

    Select an answer first
  3. 28expert · hard

    An examiner needs to acquire a Mac's disk while preserving the integrity of the evidence. The Mac is running macOS Catalina and uses APFS. Which acquisition method is most defensible in court?

    Select an answer first
  4. 29foundation · easy

    Which macOS database stores user login history, including successful and failed login attempts?

    Select an answer first
  5. 30expert · hard

    A Mac was seized while running, and the examiner needs to capture the contents of RAM. Which method is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.