
EC-CouncilDigital Forensics Essentials
Domain 4Objective 3
Web Browser Forensics DFE Practice Questions (Page 3)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 11–15
- 11
An examiner is investigating a case where a user allegedly accessed a website during a specific time window. The user claims they were using Chrome's Incognito mode. The examiner finds that the Chrome History database has no entries for that time window, but the pagefile.sys contains fragments of the website's content. What is the most reasonable conclusion?
Select an answer first - 12
A forensic examiner is investigating a case where a suspect used Firefox on a Linux system to download a file. The examiner has the disk image and needs to prove the download occurred and identify the source URL. The 'places.sqlite' database has been deleted by the suspect. What is the most effective alternative approach?
Select an answer first - 13
When a user browses in Chrome's Incognito mode, which of the following artifacts is typically NOT written to disk?
Select an answer first - 14
What type of information is typically stored in a browser cookie that is relevant to forensic analysis?
Select an answer first - 15
What type of data can be recovered from browser form autofill records?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.