
EC-CouncilCertified Security Specialist
Domain 5Objective 4
Data Acquisition and Duplication ECSS Practice Questions (Page 1)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
43questions here
9free pages
9concepts
Questions 1–5
- 1
An examiner needs to acquire only the active files from a suspect's USB drive to quickly check for specific documents, while preserving the ability to verify the acquired data later. The drive is small and time is limited. Which acquisition method and integrity check should be used?
Select an answer first - 2
When would a forensic examiner choose a sparse acquisition over a physical acquisition?
Select an answer first - 3
A forensic examiner is about to image a SATA hard drive from a seized computer. The examiner wants to ensure that no data on the original drive is modified during the acquisition and that the resulting image is verifiable. Which combination of tools and procedures should be used?
Select an answer first - 4
A forensic examiner has created an E01 image of a suspect's drive. The examiner wants to verify that the image has not been corrupted during storage. Which feature of the E01 format should the examiner use?
Select an answer first - 5
Which of the following should be documented in a chain of custody record during the acquisition process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.