Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 5Objective 2

Computer Forensics Investigation Process ECSS Practice Questions (Page 9)

Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.

44questions here
9free pages
5concepts

Questions 41–44

  1. 41foundation · easy

    Which technique is commonly used during the analysis phase to recover deleted files from a forensic image?

    Select an answer first
  2. 42application · medium

    A forensic analyst is acquiring the hard drive of a server that is still running critical services. The analyst needs to minimize disruption while preserving evidence. Which approach is most appropriate?

    Select an answer first
  3. 43application · medium

    A forensic examiner is acquiring a hard drive from a suspect's computer. The examiner uses a hardware write-blocker and creates a forensic image. Later, the examiner computes a hash of the original drive and the image. Why is this hash comparison performed?

    Select an answer first
  4. 44foundation · easy

    What is the primary purpose of maintaining a chain of custody document during the collection and acquisition of digital evidence?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to ECSS

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.