
EC-CouncilCertified Security Specialist
Domain 6Objective 2
Linux and Mac Forensics ECSS Practice Questions (Page 10)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
8concepts
Questions 46–50
- 46
During a Linux incident response, you need to determine if a specific process was running at the time of the incident. The system has been rebooted since the incident. Which source of evidence would be most useful?
Select an answer first - 47
A Linux server is suspected of running a rootkit that hides processes. The investigator has a memory dump and a disk image. The investigator wants to identify hidden processes. Which approach is most effective?
Select an answer first - 48
A Linux server was compromised. The attacker deleted logs, modified user accounts, and attempted to hide files. The investigator has a forensic image of the disk. The investigator needs to build a timeline of activity. Which combination of artifacts would provide the most comprehensive timeline?
Select an answer first - 49
An investigator is analyzing a Mac system to determine if a user accessed a specific file on a USB drive. The system uses unified logging. Which command would be most effective in finding evidence of this access?
Select an answer first - 50
An investigator is examining a Mac system to determine which applications a user has installed and when they were first used. Which combination of artifacts would provide the most comprehensive evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.