
EC-CouncilCertified Security Specialist
Domain 5Objective 1
Computer Forensics Fundamentals ECSS Practice Questions (Page 8)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
43questions here
9free pages
5concepts
Questions 36–40
- 36
A company experiences a ransomware attack. The incident response team contains the threat and restores systems from backups. Later, the legal department wants to know how the attacker gained access. Which activity would BEST support this investigation?
Select an answer first - 37
A forensic examiner is investigating a case where the suspect's computer has a solid-state drive (SSD). The examiner needs to recover deleted files. What is the MOST important consideration?
Select an answer first - 38
A security analyst detects suspicious network traffic and suspects a breach. The analyst isolates the affected system and begins collecting logs and memory dumps. This activity is BEST classified as:
Select an answer first - 39
A forensic investigator is analyzing a hard drive that was seized from a suspect. The investigator finds a file that appears to be a deleted document. The file's metadata shows a creation date that is after the suspect's arrest. What should the investigator conclude?
Select an answer first - 40
What is the primary difference between computer forensics and incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.