
EC-CouncilDigital Forensics Essentials
Domain 2Objective 4
Types and Methods of Data Acquisition DFE Practice Questions (Page 3)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
41questions here
9free pages
10concepts
Questions 11–15
- 11
Which imaging method would capture deleted files and unallocated space?
Select an answer first - 12
A forensic examiner receives a computer that was found powered off at a crime scene. The examiner must preserve the evidence in a way that allows for later analysis of deleted files. Which acquisition method should be used?
Select an answer first - 13
An incident response team is investigating a compromised web server that is still running. The team needs to capture the current state of the system, including running processes, network connections, and the contents of memory. Which type of acquisition should the team perform?
Select an answer first - 14
Which command-line tool is commonly used in Linux for creating a forensic image of a storage device?
Select an answer first - 15
What is the key difference between physical and logical imaging?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.