
EC-CouncilCertified Security Specialist
Domain 5Objective 2
Computer Forensics Investigation Process ECSS Practice Questions (Page 1)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
5concepts
Questions 1–5
- 1
A forensic investigator is writing the final report for a case. The report includes the findings, the tools used, and the chain of custody. Which additional element is REQUIRED for the report to be considered complete and professional?
Select an answer first - 2
A forensic team is collecting evidence from a large enterprise network. The suspect's workstation is in a remote office, and the corporate policy requires that the workstation remain available for business operations. The investigation is time-sensitive. Which collection method best satisfies both the investigation and business needs?
Select an answer first - 3
What is the primary purpose of creating a cryptographic hash (e.g., SHA-256) of digital evidence during the identification and preservation phase?
Select an answer first - 4
A forensic examiner must present findings in a civil lawsuit. The opposing counsel challenges the admissibility of the evidence. What should the examiner have done to ensure the evidence is admissible?
Select an answer first - 5
A forensic team is collecting evidence from a corporate office. They have identified a USB drive on the suspect's desk. What is the correct procedure for handling this evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.