
EC-CouncilDigital Forensics Essentials
Domain 6Objective 2
Tor Browser Forensics DFE Practice Questions (Page 5)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
47questions here
10free pages
10concepts
Questions 21–25
- 21
A network administrator is trying to block Tor usage on their corporate network. They have identified that Tor Browser uses a directory of relays to establish circuits. Which approach is most effective for detecting and blocking Tor connections at the network level?
Select an answer first - 22
Where can a forensic examiner typically find the Tor daemon's log file on a Windows system?
Select an answer first - 23
Which configuration file in the Tor Browser bundle contains settings for the Tor daemon, such as the location of the log file?
Select an answer first - 24
A network forensic analyst is examining a PCAP file from a corporate network. They see a series of TLS connections to a single IP address on port 443. The connections have a consistent TLS fingerprint that matches Tor's known fingerprint. However, the analyst also notices that the connections are short-lived and occur at irregular intervals. Which conclusion is most appropriate?
Select an answer first - 25
A forensic examiner is analyzing a Tor Browser installation on a Linux system. The examiner wants to recover the user's browsing history. Which file should the examiner examine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.