Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 6Objective 2

Tor Browser Forensics DFE Practice Questions (Page 10)

Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.

47questions here
10free pages
10concepts

Questions 46–47

  1. 46application · medium

    A forensic examiner is analyzing a Tor Browser installation on a Windows system. The examiner wants to determine if the user configured any custom bridges or relays. Which file should the examiner examine?

    Select an answer first
  2. 47expert · hard

    A network forensic analyst is reviewing a PCAP file and notices a series of TLS connections to a single IP address on port 443, each with a different Server Name Indication (SNI) field. The connections occur every few minutes and have consistent packet sizes. The analyst suspects Tor Browser usage. Which additional observation would most strongly support this hypothesis?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to DFE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.