
EC-CouncilCertified Security Specialist
Domain 5Objective 5
Defeating Anti-Forensics Techniques ECSS Practice Questions (Page 4)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 16–20
- 16
A security team is investigating a potential insider threat. The team suspects that an employee has been clearing the Windows Event Logs on their workstation to hide unauthorized activity. The team has access to the workstation but must not alert the employee. What is the best approach to gather evidence without alerting the suspect?
Select an answer first - 17
Which anti-forensic technique involves altering or deleting entries in system logs to remove traces of malicious activity?
Select an answer first - 18
Which practice is essential to preserve the integrity of digital evidence during acquisition?
Select an answer first - 19
What is a common anti-forensic action related to logs?
Select an answer first - 20
A security analyst is investigating a breach. The attacker deleted several log files and overwrote parts of the event log. The analyst needs to determine what the attacker did. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.