
EC-CouncilDigital Forensics Essentials
Domain 4Objective 3
Web Browser Forensics DFE Practice Questions (Page 7)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 31–35
- 31
During an investigation, you find a cookie file from a banking website. You need to determine whether the user was authenticated at the time of the cookie's creation. Which piece of information from the cookie would be most useful?
Select an answer first - 32
An examiner is analyzing a suspect's Chrome profile on a Windows system. The examiner wants to determine which websites the user was logged into and for how long the session cookies were valid. Which artifact(s) should the examiner examine?
Select an answer first - 33
An examiner is analyzing a macOS system. The user used Safari to stream a video. The examiner needs to prove that the video was watched. The examiner finds that the Safari cache contains video segments, but the history database has no entry for the video URL. What is the most likely explanation?
Select an answer first - 34
Your forensic lab receives a case involving a Linux system with multiple browsers installed (Firefox, Chrome, and Chromium). You need to quickly collect and analyze browser artifacts from all three browsers. Which approach is most efficient?
Select an answer first - 35
In the context of browser forensics, what does a session cookie indicate when found on a suspect's computer?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.