
EC-CouncilDigital Forensics Essentials
Domain 6Objective 2
Tor Browser Forensics DFE Practice Questions (Page 4)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
47questions here
10free pages
10concepts
Questions 16–20
- 16
What is the purpose of Tor Browser's randomized browser fingerprint?
Select an answer first - 17
A forensic analyst is examining a Linux system where the user downloaded and ran Tor Browser. The analyst wants to find the user's browsing history and any saved passwords. Which directory should the analyst examine first?
Select an answer first - 18
A forensic examiner is investigating a Tor Browser installation on a macOS system. The examiner wants to recover the user's saved passwords. Which file should the examiner look for?
Select an answer first - 19
What is a significant limitation when trying to identify a user from Tor Browser activity?
Select an answer first - 20
A network analyst is monitoring traffic from a corporate workstation that is suspected of using Tor Browser. The analyst observes periodic TLS connections to a single IP address on port 443, each with a distinctive TLS handshake pattern. The connections do not appear to be to any known corporate service. Which indicator is most characteristic of Tor traffic?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.