Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 5

Mac Forensics DFE Practice Questions (Page 7)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 31–35

  1. 31expert · hard

    A forensic examiner is trying to reconstruct the timeline of a user's activities on a Mac. Which combination of artifacts would provide the most comprehensive timeline?

    Select an answer first
  2. 32expert · hard

    A forensic examiner is investigating a Mac where a user allegedly accessed sensitive files. The examiner has a full disk image and needs to determine if the user accessed a specific file, but the file's access timestamp has not been updated due to the 'noatime' mount option. Which alternative artifacts should the examiner analyze to prove access?

    Select an answer first
  3. 33foundation · easy

    Which command-line tool in macOS is used to view and modify extended attributes of files?

    Select an answer first
  4. 34expert · hard

    A forensic analyst is investigating a Mac and needs to determine if a user logged in at a specific time. The analyst has the unified log, but the user's account is a standard user. Which log entry would provide the most reliable evidence of the login?

    Select an answer first
  5. 35expert · hard

    A forensic analyst is examining a Mac and finds a file with a creation timestamp that is earlier than the installation date of the operating system. What is the most likely explanation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.