
EC-CouncilCertified Security Specialist
Domain 5Objective 3
Hard Disks and File Systems ECSS Practice Questions (Page 4)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
33questions here
7free pages
4concepts
Questions 16–20
- 16
Which area of a hard disk is often examined by forensic investigators because it can contain hidden data that is not visible in the normal file system?
Select an answer first - 17
A forensic examiner is documenting the physical layout of a seized hard drive. The drive has 4 platters, 8 heads, and 1,024 cylinders. During analysis, the examiner needs to identify the total number of tracks on the drive. Which calculation is correct?
Select an answer first - 18
A forensic lab receives a USB drive that was used to transfer evidence between Windows and Linux systems. The drive is formatted with exFAT. The examiner needs to recover a deleted file that was stored in multiple non-contiguous clusters. Which characteristic of exFAT is most relevant to the recovery effort?
Select an answer first - 19
An examiner is investigating a suspect's external drive formatted with NTFS. The examiner finds a deleted file that was stored in a single cluster, but the MFT record has been reused by another file. The original data cluster is still intact. Which technique is most appropriate to recover the file content?
Select an answer first - 20
In a file system, what is the primary purpose of file metadata?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.