
EC-CouncilDigital Forensics Essentials
Domain 4Objective 5
Mac Forensics DFE Practice Questions (Page 8)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 36–40
- 36
Which forensic tool is specifically designed to acquire and analyze data from macOS systems, including file system and memory analysis?
Select an answer first - 37
A forensic examiner is analyzing an APFS volume and needs to recover a deleted file. The examiner knows the file was recently deleted, but the volume has been mounted and used since deletion. Which recovery approach is most likely to succeed?
Select an answer first - 38
A forensic analyst needs to determine which USB devices were connected to a Mac and when. Which artifact would provide this information?
Select an answer first - 39
Which file in a macOS user's Library folder contains the browsing history for the Safari web browser?
Select an answer first - 40
Which macOS log file is the primary source for system-level event messages such as kernel and application errors?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.