Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 5

Mac Forensics DFE Practice Questions (Page 8)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 36–40

  1. 36foundation · easy

    Which forensic tool is specifically designed to acquire and analyze data from macOS systems, including file system and memory analysis?

    Select an answer first
  2. 37expert · hard

    A forensic examiner is analyzing an APFS volume and needs to recover a deleted file. The examiner knows the file was recently deleted, but the volume has been mounted and used since deletion. Which recovery approach is most likely to succeed?

    Select an answer first
  3. 38application · medium

    A forensic analyst needs to determine which USB devices were connected to a Mac and when. Which artifact would provide this information?

    Select an answer first
  4. 39foundation · easy

    Which file in a macOS user's Library folder contains the browsing history for the Safari web browser?

    Select an answer first
  5. 40foundation · easy

    Which macOS log file is the primary source for system-level event messages such as kernel and application errors?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.