
EC-CouncilCertified Security Specialist
Domain 5Objective 3
Hard Disks and File Systems ECSS Practice Questions (Page 1)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
33questions here
7free pages
4concepts
Questions 1–5
- 1
A forensic examiner is analyzing a disk image and needs to determine the cluster size of an NTFS volume. Which structure or field provides this information directly?
Select an answer first - 2
A forensic examiner is analyzing a FAT32 volume and finds a deleted file's directory entry. The entry indicates the starting cluster number, but the FAT entries for the file's clusters have been zeroed. The file was stored in multiple non-contiguous clusters. Which recovery approach is most likely to succeed?
Select an answer first - 3
During an investigation, an examiner finds a file that was deleted from an NTFS volume. The file's MFT record has been reused by another file, but the original data clusters are still intact in unallocated space. Which technique is most appropriate to recover the file content?
Select an answer first - 4
A forensic examiner is comparing the file systems of two seized drives: one is FAT32 and the other is NTFS. The examiner needs to recover deleted files from both. Which statement accurately describes a key difference that affects the recovery process?
Select an answer first - 5
A forensic examiner is analyzing a Linux system that uses ext4. The examiner needs to recover a deleted file that was stored in a directory. The file's inode is still present but marked as free. Which statement best describes the recovery challenge?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.