
EC-CouncilDigital Forensics Essentials
Domain 4Objective 3
Web Browser Forensics DFE Practice Questions (Page 8)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 36–40
- 36
A suspect claims they used Chrome's Incognito mode to browse a website, and therefore no evidence exists. During analysis, you find that the website's content is partially present in the pagefile.sys. What does this indicate?
Select an answer first - 37
Which of the following is a common file format used by Chrome to store cached web content on disk?
Select an answer first - 38
During an investigation, an examiner finds that a suspect used Firefox on a Windows machine to view potentially incriminating images. The images are no longer in the browser's cache directory. Where might the examiner still find remnants of these images?
Select an answer first - 39
What is the primary advantage of using a specialized browser forensics tool over manually parsing browser databases?
Select an answer first - 40
A forensic examiner needs to collect browser artifacts from a Windows 10 workstation used by a suspect. The examiner must preserve the original timestamps of the artifacts and avoid altering file access times. Which approach best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.