
EC-CouncilCertified Security Specialist
Domain 5Objective 4
Data Acquisition and Duplication ECSS Practice Questions (Page 8)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
43questions here
9free pages
9concepts
Questions 36–40
- 36
What does it indicate if the hash value of an acquired forensic image matches the hash value of the original storage media?
Select an answer first - 37
An incident responder is called to a small office where an employee is suspected of leaking sensitive documents. The employee's workstation is powered on and the user is actively working. The responder needs to preserve volatile data and capture the system state without shutting it down. Which acquisition approach should the responder use?
Select an answer first - 38
Why is data acquisition considered a critical first step in a digital forensics investigation?
Select an answer first - 39
A forensic examiner is investigating a case involving a large RAID server. The server is still running, and the examiner needs to preserve evidence without disrupting the business. The RAID array is critical and cannot be taken offline. The examiner needs to acquire data that includes active files and deleted files that may still be present in unallocated space. Which acquisition approach should the examiner use?
Select an answer first - 40
A junior forensic examiner is asked to create a forensic image of a USB drive that is connected to a forensic workstation. The examiner wants to use a tool that can create a raw image and also compute a hash of the image in one step. Which tool should the examiner use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.