
EC-CouncilDigital Forensics Essentials
Domain 2Objective 4
Types and Methods of Data Acquisition DFE Practice Questions (Page 7)
Part of the Storage Media and Data Acquisition domain, which makes up ~12% of our current practice bank.
41questions here
9free pages
10concepts
Questions 31–35
- 31
Which statement best defines data acquisition in the context of digital forensics?
Select an answer first - 32
Which of the following is a commonly used tool for data acquisition in digital forensics?
Select an answer first - 33
A forensic examiner is acquiring a hard drive from a seized computer. The examiner connects the drive to a forensic workstation using a hardware write-blocker. During the acquisition, the examiner notices that the write-blocker is not functioning correctly and the drive is being mounted as read-write by the operating system. What should the examiner do?
Select an answer first - 34
A corporate investigator needs to collect only the emails and chat logs from an employee's laptop for a policy violation investigation. The laptop is currently running, and the investigator wants to minimize disruption to the employee's work. The company policy requires that the collected data be verifiable. Which acquisition method is most appropriate?
Select an answer first - 35
A forensic examiner is called to a scene where a computer is still running and the suspect may have encrypted files. The examiner needs to preserve evidence while minimizing changes to the system. Which acquisition approach should be used first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.