Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 6Objective 2

Tor Browser Forensics DFE Practice Questions (Page 5)

Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.

47questions here
10free pages
10concepts

Questions 21–25

  1. 21application · medium

    A network administrator is trying to block Tor usage on their corporate network. They have identified that Tor Browser uses a directory of relays to establish circuits. Which approach is most effective for detecting and blocking Tor connections at the network level?

    Select an answer first
  2. 22foundation · easy

    Where can a forensic examiner typically find the Tor daemon's log file on a Windows system?

    Select an answer first
  3. 23foundation · easy

    Which configuration file in the Tor Browser bundle contains settings for the Tor daemon, such as the location of the log file?

    Select an answer first
  4. 24expert · hard

    A network forensic analyst is examining a PCAP file from a corporate network. They see a series of TLS connections to a single IP address on port 443. The connections have a consistent TLS fingerprint that matches Tor's known fingerprint. However, the analyst also notices that the connections are short-lived and occur at irregular intervals. Which conclusion is most appropriate?

    Select an answer first
  5. 25application · medium

    A forensic examiner is analyzing a Tor Browser installation on a Linux system. The examiner wants to recover the user's browsing history. Which file should the examiner examine?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.