
EC-CouncilCertified Security Specialist
Domain 5Objective 4
Data Acquisition and Duplication ECSS Practice Questions (Page 6)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
43questions here
9free pages
9concepts
Questions 26–30
- 26
Which forensic acquisition tool is known for its graphical interface and ability to create images in multiple formats, including E01 and raw?
Select an answer first - 27
A forensic examiner needs to create a bit-for-bit image of a suspect's SATA hard drive. The drive is known to be in a write-protected state, but the examiner wants to ensure no data is altered during acquisition. Which tool should be used to connect the drive to the forensic workstation?
Select an answer first - 28
Which of the following is a key difference between hardware and software write blockers?
Select an answer first - 29
Why are cryptographic hashes such as MD5, SHA-1, and SHA-256 used during data acquisition?
Select an answer first - 30
When is static (dead) acquisition most appropriate in a digital forensics investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.