Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 3

Web Browser Forensics DFE Practice Questions (Page 6)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 26–30

  1. 26application · medium

    You are analyzing a forensic image from a macOS system. The user's default browser is Safari. You need to extract the browsing history to determine which websites were visited. Which approach is most appropriate?

    Select an answer first
  2. 27expert · hard

    An examiner is analyzing a Windows system. The user is suspected of downloading a file from a website. The examiner finds the file on the system, but the Chrome download history is empty. The user claims they used Chrome's Incognito mode. What is the most likely explanation?

    Select an answer first
  3. 28foundation · easy

    Which browser artifact would a forensic examiner analyze to determine the exact files a user downloaded from the internet?

    Select an answer first
  4. 29foundation · easy

    Which of the following is a limitation of private browsing modes that forensic examiners can exploit?

    Select an answer first
  5. 30application · medium

    An examiner is working on a case involving a macOS user who primarily uses Safari. The examiner needs to collect browser artifacts without altering the evidence. Which of the following is the most appropriate first step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.