
EC-CouncilDigital Forensics Essentials
Domain 2Objective 4
Types and Methods of Data Acquisition DFE Practice Questions (Page 6)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
41questions here
9free pages
10concepts
Questions 26–30
- 26
An examiner is investigating a large RAID array where the relevant evidence is spread across multiple specific files. The array is too large to image entirely within the available time and storage capacity. The examiner must decide between sparse acquisition and logical acquisition. Which factor most strongly favors sparse acquisition over logical acquisition?
Select an answer first - 27
Why is write protection important during data acquisition?
Select an answer first - 28
A forensic examiner needs to collect only the emails and chat logs from a suspect's computer that is currently running. The examiner wants to minimize the amount of data collected while ensuring the selected files are preserved. Which acquisition method is most appropriate?
Select an answer first - 29
What is the purpose of using a write blocker during forensic acquisition?
Select an answer first - 30
An incident responder discovers that a critical server is still running and contains volatile data, including active network connections and running processes. The organization requires that the server remain online to continue providing services. Which acquisition approach should the responder use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.