Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 5Objective 5

Defeating Anti-Forensics Techniques ECSS Practice Questions (Page 3)

Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.

45questions here
9free pages
8concepts

Questions 11–15

  1. 11application · medium

    A system administrator notices that the Windows Event Log on a critical server is missing entries for a 3-hour period during the night. The server was not rebooted and no maintenance was scheduled. Which action should the administrator take to investigate potential log tampering?

    Select an answer first
  2. 12foundation · easy

    Which sign might indicate that a file is encrypted and could hinder forensic acquisition?

    Select an answer first
  3. 13expert · hard

    During a forensic examination of a Windows system, the investigator finds a hidden partition that is not visible in the operating system. The investigator needs to acquire the hidden partition without altering it. Which method is most appropriate?

    Select an answer first
  4. 14foundation · easy

    What is a common indicator that a system may be using full disk encryption?

    Select an answer first
  5. 15application · medium

    A security analyst is investigating a data breach and suspects that the attacker used anti-forensic techniques to slow down the investigation. The analyst notices that the system has multiple encrypted containers and that the event logs have been partially cleared. Which anti-forensic goal is the attacker most likely trying to achieve?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.