Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 3Objective 3

Steganography and Data Hiding Techniques DFE Practice Questions (Page 6)

Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.

50questions here
10free pages
9concepts

Questions 26–30

  1. 26foundation · easy

    Which of the following is a recognized type of steganography?

    Select an answer first
  2. 27expert · hard

    A forensic examiner is analyzing a set of images that may contain hidden data. The examiner has limited time and must prioritize which images to analyze first. The images include a high-resolution photo, a low-resolution logo, and a screenshot of a text document. Which image is most likely to contain hidden data, and why?

    Select an answer first
  3. 28application · medium

    A network forensic analyst is reviewing a packet capture and notices that TCP packets have unusual values in the header fields, such as the sequence number and window size. The analyst suspects network steganography. Which approach is most effective to confirm the hidden data?

    Select an answer first
  4. 29foundation · easy

    What is slack space in the context of file system steganography?

    Select an answer first
  5. 30application · medium

    A network administrator discovers that an employee has been sending WAV audio files to an external party. The files sound like normal music but are slightly larger than expected. The administrator suspects data exfiltration. Which technique is most likely being used, and what should the administrator do to confirm?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.