
EC-CouncilCertified Security Specialist
Domain 5Objective 5
Defeating Anti-Forensics Techniques ECSS Practice Questions (Page 3)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 11–15
- 11
A system administrator notices that the Windows Event Log on a critical server is missing entries for a 3-hour period during the night. The server was not rebooted and no maintenance was scheduled. Which action should the administrator take to investigate potential log tampering?
Select an answer first - 12
Which sign might indicate that a file is encrypted and could hinder forensic acquisition?
Select an answer first - 13
During a forensic examination of a Windows system, the investigator finds a hidden partition that is not visible in the operating system. The investigator needs to acquire the hidden partition without altering it. Which method is most appropriate?
Select an answer first - 14
What is a common indicator that a system may be using full disk encryption?
Select an answer first - 15
A security analyst is investigating a data breach and suspects that the attacker used anti-forensic techniques to slow down the investigation. The analyst notices that the system has multiple encrypted containers and that the event logs have been partially cleared. Which anti-forensic goal is the attacker most likely trying to achieve?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.