
EC-CouncilCertified Security Specialist
Domain 6Objective 2
Linux and Mac Forensics ECSS Practice Questions (Page 1)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
8concepts
Questions 1–5
- 1
Which file system was the primary default for macOS before the introduction of APFS?
Select an answer first - 2
During a Mac forensic investigation, you suspect that a malicious process is running but hiding its executable from the filesystem. Which technique would be most effective in identifying this process?
Select an answer first - 3
A Linux administrator wants to review authentication-related events, such as successful and failed login attempts. Which log file typically contains this information?
Select an answer first - 4
A Linux server was compromised, and the attacker deleted several critical files. The incident responder needs to recover deleted files from an ext4 filesystem. The server is still running, and the filesystem is mounted. Which approach is most appropriate for the responder to attempt first?
Select an answer first - 5
A Mac forensic examiner needs to determine which files a user accessed on an APFS volume. The examiner has a full disk image. Which feature of APFS can provide historical versions of files and directories, potentially revealing earlier access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.