
EC-CouncilDigital Forensics Essentials
Domain 3Objective 2
Password Protection and Encryption Techniques DFE Practice Questions (Page 2)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 6–10
- 6
A forensic examiner has recovered a password hash from a system. The examiner knows the password policy requires at least 8 characters, including uppercase, lowercase, digits, and special characters. Which cracking strategy is most likely to succeed in a reasonable time?
Select an answer first - 7
A forensic examiner has imaged a laptop that uses BitLocker full-disk encryption. The user's password is unknown, but the examiner has a memory dump taken from the laptop while it was running. Which approach is most likely to recover the encryption key and allow access to the image?
Select an answer first - 8
A forensic examiner has obtained a court order to search a suspect's computer. The computer is protected by a password, and the examiner wants to bypass it to access the data. Which action is legally and ethically appropriate?
Select an answer first - 9
Which method is used to recover encryption keys from a running system by analyzing the contents of RAM?
Select an answer first - 10
An organization is migrating to full-disk encryption on all laptops. They are concerned about the impact on forensic investigations if a laptop is seized. What should they do to prepare?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.