
EC-CouncilCertified Security Specialist
Domain 6Objective 2
Linux and Mac Forensics ECSS Practice Questions (Page 9)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
8concepts
Questions 41–45
- 41
A forensic analyst is investigating a Linux system where an attacker is suspected of creating a backdoor user account. Which set of files and logs would provide the most direct evidence of this activity?
Select an answer first - 42
Which macOS database stores user account information, including user IDs and home directories?
Select an answer first - 43
A Linux system was compromised. The investigator has a forensic image and a memory dump. The attacker is suspected of using a compromised user account to escalate privileges and run a malicious script. The auth.log has been rotated and the old logs are unavailable. Which approach would provide the most reliable evidence of the privilege escalation?
Select an answer first - 44
A Mac was used to access sensitive files, and the investigator needs to determine if the user copied files to an external drive. The investigator has a full disk image. Which combination of artifacts would provide the strongest evidence?
Select an answer first - 45
During a Mac forensic investigation, you need to determine if a specific application was running at the time of a security incident. The system has been rebooted since the incident. Which source of evidence would be most useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.