
EC-CouncilCertified Security Specialist
Domain 5Objective 2
Computer Forensics Investigation Process ECSS Practice Questions (Page 9)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
5concepts
Questions 41–44
- 41
Which technique is commonly used during the analysis phase to recover deleted files from a forensic image?
Select an answer first - 42
A forensic analyst is acquiring the hard drive of a server that is still running critical services. The analyst needs to minimize disruption while preserving evidence. Which approach is most appropriate?
Select an answer first - 43
A forensic examiner is acquiring a hard drive from a suspect's computer. The examiner uses a hardware write-blocker and creates a forensic image. Later, the examiner computes a hash of the original drive and the image. Why is this hash comparison performed?
Select an answer first - 44
What is the primary purpose of maintaining a chain of custody document during the collection and acquisition of digital evidence?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECSS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.