Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 2

Linux and Mac Forensics ECSS Practice Questions (Page 2)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

53questions here
11free pages
8concepts

Questions 6–10

  1. 6expert · hard

    A Mac system was compromised. The investigator has a full disk image and a memory dump. The attacker is suspected of using a legitimate application to exfiltrate data. The user's ~/Library/Preferences/com.apple.finder.plist has been modified. Which approach would provide the most reliable evidence of the exfiltration activity?

    Select an answer first
  2. 7foundation · easy

    In Linux, which file stores user account information, including user IDs and home directories?

    Select an answer first
  3. 8application · medium

    During a Linux forensic investigation, you need to recover a deleted file from an ext4 filesystem. The file was deleted recently, and the system has been powered off since the deletion. Which approach would be most likely to recover the file?

    Select an answer first
  4. 9application · medium

    A Mac was used to browse the internet, and the investigator needs to recover the browsing history. Which file or database would contain this information?

    Select an answer first
  5. 10foundation · easy

    Which command-line utility is used to query the unified log system on modern macOS?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.