
EC-CouncilDigital Forensics Essentials
Domain 3Objective 2
Password Protection and Encryption Techniques DFE Practice Questions (Page 3)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 11–15
- 11
A forensic examiner is trying to crack a password hash that is known to be unsalted. The examiner has a large precomputed table of hash-to-password mappings. Which technique should they use?
Select an answer first - 12
A forensic examiner has acquired an image of a suspect's laptop. The user account is protected by a password, and the examiner needs to access the files for analysis. The examiner has a list of common passwords and wants to try them in a systematic way. Which approach is most appropriate for this situation?
Select an answer first - 13
A forensic examiner has a memory dump from a system that uses full-disk encryption (FDE). The examiner needs to decrypt the disk image. Which approach is most likely to yield the encryption key?
Select an answer first - 14
Which countermeasure is most effective in preventing an attacker from using a cold boot attack to recover encryption keys?
Select an answer first - 15
A company needs to securely transfer a large file to a partner. They want to use encryption that is fast for bulk data and uses a shared secret key. Which encryption algorithm is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.