
EC-CouncilCertified Security Specialist
Domain 6Objective 2
Linux and Mac Forensics ECSS Practice Questions (Page 11)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
8concepts
Questions 51–53
- 51
An analyst is investigating a Mac and wants to determine which applications were installed and when they were last used. Which files or databases would provide this information?
Select an answer first - 52
A Linux server was breached. The attacker used stolen credentials to log in via SSH, then escalated privileges and ran commands. The investigator has the disk image and a memory dump. The attacker attempted to delete logs. Which evidence source is most likely to still contain traces of the attacker's commands?
Select an answer first - 53
During a Linux forensic investigation, which structure within the ext4 file system is primarily responsible for tracking which blocks are allocated to each file?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECSS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.