
EC-CouncilCertified Security Specialist
Domain 5Objective 2
Computer Forensics Investigation Process ECSS Practice Questions (Page 5)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
5concepts
Questions 21–25
- 21
An investigator is called to a crime scene where a computer is running and the screen shows an open email account. The suspect is not present. Which action should the investigator take to preserve volatile evidence?
Select an answer first - 22
During a forensic investigation, the investigator finds a file that appears to be relevant. The file is on a network share that is still accessible. What should the investigator do to preserve this evidence?
Select an answer first - 23
A company is investigating a data breach. The forensic team has already identified the affected systems and preserved the evidence. They are now in the process of extracting relevant information from the acquired images. Which phase of the computer forensics investigation process does this represent?
Select an answer first - 24
A forensic examiner needs to acquire the contents of a suspect's laptop hard drive. The laptop is running and the user is logged in. The examiner wants to preserve the integrity of the evidence and maintain a proper chain of custody. Which step should the examiner perform FIRST?
Select an answer first - 25
A forensic examiner has completed the analysis and must write the final report. The report will be read by both technical and non-technical audiences. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.