Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 2

Linux and Mac Forensics ECSS Practice Questions (Page 11)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

53questions here
11free pages
8concepts

Questions 51–53

  1. 51application · medium

    An analyst is investigating a Mac and wants to determine which applications were installed and when they were last used. Which files or databases would provide this information?

    Select an answer first
  2. 52expert · hard

    A Linux server was breached. The attacker used stolen credentials to log in via SSH, then escalated privileges and ran commands. The investigator has the disk image and a memory dump. The attacker attempted to delete logs. Which evidence source is most likely to still contain traces of the attacker's commands?

    Select an answer first
  3. 53foundation · easy

    During a Linux forensic investigation, which structure within the ext4 file system is primarily responsible for tracking which blocks are allocated to each file?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to ECSS

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.