Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 2

Linux and Mac Forensics ECSS Practice Questions (Page 7)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

53questions here
11free pages
8concepts

Questions 31–35

  1. 31application · medium

    An analyst is investigating a possible brute-force attack on a Linux server. The analyst wants to identify the source IP addresses that repeatedly failed authentication and the times of those attempts. Which log file and command combination would provide the most direct evidence?

    Select an answer first
  2. 32foundation · easy

    What is the default file system used by modern macOS versions (starting with macOS High Sierra)?

    Select an answer first
  3. 33foundation · easy

    When investigating a live Linux system, which command would an examiner use to list all running processes with their process IDs?

    Select an answer first
  4. 34application · medium

    A forensic analyst is investigating a Mac system to determine when a specific application was first launched. The system uses unified logging. Which command would be most effective in finding this information?

    Select an answer first
  5. 35foundation · easy

    A forensic examiner needs to identify the Linux file system type on a seized drive. Which file system is the default for most modern Linux distributions and supports journaling?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.