
EC-CouncilCertified Security Specialist
Domain 6Objective 2
Linux and Mac Forensics ECSS Practice Questions (Page 4)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
8concepts
Questions 16–20
- 16
Which Linux file contains the encrypted password hashes for user accounts and is readable only by privileged users?
Select an answer first - 17
A Linux server was compromised, and the investigator needs to determine when a specific file was first created on the ext4 filesystem. The file's modification time has been altered by the attacker. Which forensic approach would provide the most reliable evidence of the file's original creation timeframe?
Select an answer first - 18
A Mac was compromised, and the investigator needs to capture volatile data including running processes and network connections. The Mac is currently running. Which tool is most appropriate for this task?
Select an answer first - 19
A Mac user is suspected of using a messaging app to exfiltrate data. The investigator has a full disk image and needs to find evidence of the app's usage, including messages and timestamps. Which approach would be most effective?
Select an answer first - 20
Which macOS command displays a list of running processes along with their process IDs and CPU usage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.