
EC-CouncilCertified Security Specialist
Domain 5Objective 4
Data Acquisition and Duplication ECSS Practice Questions (Page 3)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
43questions here
9free pages
9concepts
Questions 11–15
- 11
A forensic examiner is using the dd command in Linux to create an image of a hard drive. The examiner wants to ensure the image is created without modifying the original drive. What should the examiner do?
Select an answer first - 12
Which acquisition method copies only the files and folders that are currently allocated and accessible by the file system?
Select an answer first - 13
A forensic examiner is imaging a hard drive that is connected to a forensic workstation. The examiner notices that the drive is making unusual clicking sounds and suspects a hardware failure. The examiner wants to maximize the chance of recovering data while preserving the integrity of the evidence. Which approach should the examiner take?
Select an answer first - 14
What is a primary advantage of using the Advanced Forensic Format (AFF) over raw (DD) images?
Select an answer first - 15
A forensic examiner has created a raw (DD) image of a suspect's drive and an E01 image of the same drive. The examiner wants to verify that both images contain the same data. The examiner has the original drive still available. Which verification method is most reliable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.