
EC-CouncilCertified Security Specialist
Domain 5Objective 3
Hard Disks and File Systems ECSS Practice Questions (Page 7)
Part of the Digital Forensics Fundamentals and Acquisition domain, which makes up ~12% of our current practice bank.
33questions here
7free pages
4concepts
Questions 31–33
- 31
During a forensic examination of an NTFS volume, an investigator finds a file that was supposedly deleted but its data is still accessible through the filesystem. The file's MFT entry is marked as in use, but the file is not visible in any directory. Which NTFS feature best explains this situation?
Select an answer first - 32
When a file is deleted in a typical file system, what happens to the file's data blocks?
Select an answer first - 33
A forensic analyst is examining a disk image and needs to determine the cluster size of an NTFS volume. The analyst knows the volume's total size and the number of clusters. Which additional information is required to calculate the cluster size?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECSS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.