EC-COUNCIL EC-Council Digital Forensics Essentials (DFE) - 112-57 Exam Practice Test
Harry, a security professional, was hired to identify the details of an attack that was initiated on a Windows system. In this process, Harry decided to check the logs of currently running applications and the information related to previously uninstalled or removed applications for suspicious events.
Which of the following folders in a Windows system stores information on applications run on the system?
Which of the following folders in a Windows system stores information on applications run on the system?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Andrew, a system administrator, is performing a UEFI boot process. The current phase of the UEFI boot process consists of the initialization code that the system executes after powering on the EFI system. This phase also manages platform reset events and sets up the system so that it can find, validate, install, and run the PEI.
Which of the following UEFI boot phases is the process currently in?
Which of the following UEFI boot phases is the process currently in?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Identify the malware analysis technique in which the investigators must take a snapshot of the baseline state of the forensic workstation before malware execution.
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A forensic investigator is collecting volatile data such as system information and network information present in the registries, cache, DLLs, and RAM of digital devices through its normal interface.
Identify the data acquisition method the investigator is performing.
Identify the data acquisition method the investigator is performing.
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
James, a forensic specialist, was appointed to investigate an incident in an organization. As part of the investigation, James is attempting to identify whether any external storage devices are connected to the internal systems. For this purpose, he employed a utility to capture the list of all devices connected to the local machine and removed suspicious devices.
Identify the tool employed by James in the above scenario.
Identify the tool employed by James in the above scenario.
Correct Answer: C
In which of the following malware distribution techniques does the attacker use tactics such as keyword stuffing, doorway pages, page swapping, and adding unrelated keywords to improve the search-engine ranking of their malware pages?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An investigator wants to extract information about the status of the network interface cards (NICs) in an organization's Windows-based systems. Identify the command-line utility that can help the investigator detect the network status.
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which of the following tools can be used by an investigator to analyze the metadata of files in a Windows- based system?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).