Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 5Objective 5

Defeating Anti-Forensics Techniques ECSS Practice Questions (Page 5)

Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.

45questions here
9free pages
8concepts

Questions 21–25

  1. 21application · medium

    An investigator is examining a seized smartphone and finds an app that creates encrypted vaults. The investigator needs to access the data inside the vault for evidence. Which approach is most appropriate?

    Select an answer first
  2. 22application · medium

    During a forensic examination of a Windows 10 workstation, you notice that the NTFS volume has a large amount of unallocated space that does not match the expected slack based on the cluster size. The user is suspected of hiding sensitive documents. Which technique should you use to check for hidden data in the slack space?

    Select an answer first
  3. 23foundation · easy

    Which type of file is commonly used as a carrier for steganographic data?

    Select an answer first
  4. 24application · medium

    A forensic examiner is analyzing a USB drive that is suspected of containing encrypted files. The examiner finds a file with a .enc extension and no other files on the drive. Which step should the examiner take to determine if the file is encrypted?

    Select an answer first
  5. 25foundation · easy

    What is a primary goal of anti-forensics?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.