
EC-CouncilCertified Security Specialist
Domain 5Objective 5
Defeating Anti-Forensics Techniques ECSS Practice Questions (Page 9)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 41–45
- 41
A forensic examiner is investigating a case where the attacker used multiple anti-forensic techniques, including log tampering and data hiding. The examiner has a limited time budget and must decide which technique to analyze first to maximize the chance of identifying the attacker. Which approach is most effective?
Select an answer first - 42
A forensic examiner is about to acquire a hard drive from a suspect's computer. The suspect is known to use anti-forensic tools that wipe free space. What should the examiner do FIRST to preserve evidence?
Select an answer first - 43
What is the purpose of hashing a forensic image after acquisition?
Select an answer first - 44
An investigator is examining a seized laptop and finds a folder named 'Documents' that appears empty, but the folder's size on disk is several megabytes. The investigator suspects encryption or password protection. Which step should be taken first to confirm this suspicion?
Select an answer first - 45
A forensic investigator is acquiring evidence from a computer that is suspected of containing hidden data in slack space. The investigator wants to ensure that the acquisition process does not alter the evidence. Which tool or method should the investigator use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECSS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.