
EC-CouncilCertified Security Specialist
Domain 5Objective 5
Defeating Anti-Forensics Techniques ECSS Practice Questions (Page 1)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 1–5
- 1
A forensic examiner is investigating a suspect's computer. The examiner finds a file that appears to be encrypted, but the suspect claims it is just a random data file. The examiner has a memory dump from the suspect's computer. Which action is most likely to prove or disprove the claim?
Select an answer first - 2
A forensic examiner is analyzing a Windows system and finds a file that appears to be a normal text file, but its size is larger than expected. The examiner suspects that data is hidden in an alternate data stream (ADS). Which command should the examiner use to list all ADS associated with the file?
Select an answer first - 3
A forensic analyst is investigating a case involving child exploitation and finds a collection of audio files. The analyst suspects that hidden data may be embedded in the audio files using steganography. Which tool or technique is most appropriate to detect this?
Select an answer first - 4
Which file system feature allows data to be hidden in a file without being visible in normal directory listings?
Select an answer first - 5
A system administrator notices that the Windows Event Logs on a server have gaps in the timeline, and the last entry before the gap is followed by a log entry with a timestamp that is earlier than the previous one. What does this indicate, and what should the administrator do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.