
EC-CouncilCertified Security Specialist
Domain 5Objective 5
Defeating Anti-Forensics Techniques ECSS Practice Questions (Page 8)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 36–40
- 36
Which of the following is a sign that system logs may have been tampered with?
Select an answer first - 37
A forensic analyst is reviewing a set of JPEG images from a suspect's computer. One image has an unusually large file size compared to its resolution, and the color histogram shows an abnormal distribution. Which technique should the analyst use to determine if data is hidden inside the image?
Select an answer first - 38
A forensic analyst is examining a suspect's computer and finds a file that appears to be a normal image, but the analyst suspects that the file contains hidden data. The analyst also notices that the system has a tool that can create hidden partitions. Which anti-forensic technique is the suspect most likely using?
Select an answer first - 39
Which technique is used to hide a secret message inside a digital image by modifying the least significant bits of pixel data?
Select an answer first - 40
During a forensic examination of a Windows system, you notice that a file named 'notes.txt' has a size of 2 KB, but when you list its alternate data streams, you find a stream named 'hidden' with a size of 5 MB. What should you do to preserve this evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.