
EC-CouncilDigital Forensics Essentials
Domain 6Objective 2
Tor Browser Forensics DFE Practice Questions (Page 8)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
47questions here
10free pages
10concepts
Questions 36–40
- 36
During a memory forensics investigation, an examiner finds an open tab in Tor Browser displaying a dark web marketplace. The examiner also finds a string that appears to be a private key for a cryptocurrency wallet. The defense argues that the memory dump is unreliable because Tor Browser uses memory wiping. Which approach would best overcome this anti-forensic technique?
Select an answer first - 37
In memory forensics, which of the following Tor Browser traces might be found in a memory dump?
Select an answer first - 38
A forensic examiner is trying to attribute Tor Browser activity to a specific employee in a corporate environment. The Tor Browser was run from a network share, and the employee used a standard user account. The examiner has access to the employee's workstation and the network share. Which combination of evidence would provide the strongest link?
Select an answer first - 39
During an investigation, you need to determine whether a suspect's Tor Browser was configured to use a specific bridge relay. Which file should you examine to find this configuration?
Select an answer first - 40
In Tor Browser, which of the following data is considered non-persistent and is cleared when the browser is closed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.