
EC-CouncilCertified Security Specialist
Domain 6Objective 5
Dark Web Forensics ECSS Practice Questions (Page 3)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
47questions here
10free pages
8concepts
Questions 11–15
- 11
A forensic examiner is analyzing a suspect's computer and finds a file named 'torrc' in the Tor installation directory. The examiner wants to understand how the suspect configured Tor. Which information in the torrc file is most relevant for forensic analysis?
Select an answer first - 12
A forensic examiner is analyzing a network capture from a computer that was using Tor. The examiner wants to identify the destination of the user's traffic. Which information in the capture is most useful?
Select an answer first - 13
A digital forensics team is investigating an employee suspected of accessing the dark web from a company workstation. The team has access to the workstation's disk image. Which set of artifacts would be most useful to confirm the employee's dark web activity?
Select an answer first - 14
An investigator needs to capture a dark web page that is only available for a short time and requires a specific session cookie. The investigator has legal authorization. To ensure the evidence is admissible, which action is most important?
Select an answer first - 15
Which of the following is a common structural feature of dark web marketplaces?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.