
EC-CouncilCertified Security Specialist
Domain 6Objective 2
Linux and Mac Forensics ECSS Practice Questions (Page 6)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
8concepts
Questions 26–30
- 26
An investigator needs to recover a file that was recently deleted from a Mac system using APFS. The user had FileVault enabled. What is the most important consideration for the recovery attempt?
Select an answer first - 27
A forensic analyst is investigating a Linux system suspected of running a memory-resident malware. The malware is not visible in the filesystem. Which action would be most effective in identifying the malicious process?
Select an answer first - 28
A forensic analyst is investigating a Mac system to determine if a user installed a specific application. Which combination of artifacts would provide the most reliable evidence of the installation?
Select an answer first - 29
An investigator is analyzing a Mac's unified logs to determine if a specific USB device was connected. Which log subsystem or process would most likely contain this information?
Select an answer first - 30
A Linux server was breached. The investigator has a forensic image of the disk and a memory dump. The attacker is suspected of creating a new user account and using it to run a malicious process. The system's auth.log has been partially cleared. Which combination of evidence would provide the most reliable reconstruction of the attacker's actions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.