
EC-CouncilCertified Security Specialist
Domain 5Objective 2
Computer Forensics Investigation Process ECSS Practice Questions (Page 7)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
5concepts
Questions 31–35
- 31
What is the purpose of examining the Windows Registry during the analysis phase of a computer forensics investigation?
Select an answer first - 32
Which method is considered the most forensically sound for acquiring digital evidence from a computer's hard drive?
Select an answer first - 33
During the initial stages of a computer forensics investigation, which action is most appropriate to preserve the integrity of digital evidence on a powered-on computer?
Select an answer first - 34
A system administrator discovers that a server was accessed by an unauthorized user. The administrator immediately logs into the server to check running processes and takes a screenshot of the active session. Later, the incident response team arrives and begins the forensic process. Which action by the administrator most likely compromised the forensic integrity of the evidence?
Select an answer first - 35
A forensic analyst is examining a Linux system and needs to determine which users were logged in at a specific time. Which log file should the analyst examine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.