
EC-CouncilCertified Security Specialist
Domain 5Objective 5
Defeating Anti-Forensics Techniques ECSS Practice Questions (Page 2)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 6–10
- 6
A forensic examiner has a forensic image of a suspect's drive. The image contains an encrypted container file. The examiner also has a memory dump from the suspect's computer. What is the most effective way to attempt to decrypt the container?
Select an answer first - 7
What is a common countermeasure to mitigate the effects of encryption on forensic analysis?
Select an answer first - 8
Which technique is commonly used by attackers to hide data inside image or audio files without visibly altering the file's appearance?
Select an answer first - 9
A forensic examiner is investigating a case where the suspect used a tool to wipe free space on the hard drive. The examiner has already created a forensic image of the drive. What should the examiner do to maximize the chance of recovering deleted files?
Select an answer first - 10
A system administrator suspects that a user has been tampering with the Windows Event Logs to hide unauthorized access. The administrator notices that the Security log has a gap from 2:00 PM to 3:00 PM, and the last entry before the gap is event ID 4624 (successful logon). What should the administrator do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.