
EC-CouncilDigital Forensics Essentials
Domain 3Objective 3
Steganography and Data Hiding Techniques DFE Practice Questions (Page 9)
Part of the Defeating Anti-Forensics Techniques domain, which makes up ~13% of our current practice bank.
50questions here
10free pages
9concepts
Questions 41–45
- 41
A forensic examiner is analyzing a large set of images from a suspect's computer. The examiner has limited time and needs to prioritize which images to examine manually. The examiner runs Stegdetect on all images and gets a list of images with positive detections. However, the examiner knows that Stegdetect can produce false positives. Which additional step would be most effective to confirm the presence of hidden data?
Select an answer first - 42
Which tool is specifically designed for steganalysis (detecting hidden data)?
Select an answer first - 43
A security analyst is explaining to a colleague the difference between steganography and cryptography. Which statement correctly describes the primary difference?
Select an answer first - 44
A network forensic analyst is examining a packet capture and notices that the TCP window size values are unusual and vary in a pattern that correlates with the payload data. The analyst suspects network steganography. Which technique is most likely being used, and what is the best way to confirm it?
Select an answer first - 45
A network administrator notices unusual traffic patterns on a corporate network. Packets are being sent at regular intervals, but the timing between packets varies slightly in a way that seems to encode information. The payloads themselves appear normal. Which steganographic technique is being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.