Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 2

Linux and Mac Forensics ECSS Practice Questions (Page 5)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

53questions here
11free pages
8concepts

Questions 21–25

  1. 21application · medium

    A forensic examiner is analyzing an ext4 filesystem image from a compromised Linux server. The examiner wants to identify recently modified files that may indicate malicious activity. Which artifact or structure within the ext4 filesystem would provide the most useful timeline of file changes?

    Select an answer first
  2. 22application · medium

    During a forensic investigation of a Linux system, you need to determine if a user account was created by an attacker and whether that account was used to gain root privileges. Which combination of evidence sources would be most effective?

    Select an answer first
  3. 23foundation · easy

    In modern macOS, which logging system consolidates log data from various system components and applications into a single unified store?

    Select an answer first
  4. 24application · medium

    A forensic analyst is investigating a Linux system where an attacker is suspected of modifying user accounts. The analyst wants to determine if any accounts have been added or modified recently. Which files should be examined for timestamps and content?

    Select an answer first
  5. 25foundation · easy

    Which Linux log file is the primary location for general system activity messages, such as service start/stop events and application errors?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.