
EC-CouncilCertified Security Specialist
Domain 5Objective 2
Computer Forensics Investigation Process ECSS Practice Questions (Page 6)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
5concepts
Questions 26–30
- 26
An analyst is investigating a case of intellectual property theft. The suspect allegedly emailed a confidential document to a personal account. Which forensic technique would most likely reveal evidence of this activity?
Select an answer first - 27
During a forensic examination, an analyst is searching for deleted files on a Windows system. The analyst needs to recover files that were deleted from the Recycle Bin. Which technique should the analyst use?
Select an answer first - 28
A forensic investigator is handling a case where the suspect's computer was used to access a cloud storage account. The investigator has the computer's hard drive image. Which additional evidence source is most critical to preserve?
Select an answer first - 29
During which phase of a computer forensics investigation does the investigator typically create a bit-for-bit copy of the storage media?
Select an answer first - 30
Why is it important to document the tools and methods used during a computer forensics investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.