All questions

EC-Council Digital Forensics Essentials (DFE) Practice Test

Browse all practice questions for the EC-Council Digital Forensics Essentials (DFE) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

EC-Council Digital Forensics Essentials Practice Test 2026 – Complete Exam Prep course image
All questions

These questions are part of the practice quiz. Start practicing

  • During which planning step do investigators ensure evidence is collected legally and with minimal disruption?
  • Which Wireshark filter detects a SYN-FIN flood DoS attack?
  • Which command can help identify all current connections and listening ports on a system?
  • In digital forensics, what does the term "chain of custody" refer to?
  • Which attack involves trying multiple password combinations to gain access to an account?
  • Which type of data is triggered by tools like Snort IDS that inspect network traffic?
  • In which UEFI boot process phase is the UEFI program cleared from memory and control is transferred to the OS?
  • Who is responsible for performing data acquisition in a cybercrime investigation?
  • What command does Edwin use to retrieve the routing table and check for persistent routes?
  • Identify the professional Johnson approached for legal advice before conducting an investigation.
  • In which data acquisition technique can the geometry of the target disk be modified to align with the suspected drive?
  • What tool did Brennan, a digital forensics investigator, use to automate the scanning of a suspected malware-infected machine?
  • What cmdlet did Serah use to parse the GPTs of the hard disks and analyze the boot sector?
  • Which country has the "Regulation of Investigatory Powers Act 2000" related to cyber law?
  • What key consideration does Joshua emphasize by recruiting experienced individuals for his forensic lab?
  • In the TCP/IP model, what layer is responsible for the movement of data packets using protocols like IP and ARP?
  • What is the primary goal of Rule 102 of the Federal Rules of Evidence?
  • What kind of analysis does Bayesian correlation perform?
  • During which event correlation step did Raphael identify the cause of the network access issue?
  • In which forensic readiness planning step do investigators evaluate what occurs with potential evidence data?
  • What type of information does the $mft file store in an NTFS file system?
  • When a hacker sends a legitimate-looking email with malicious links to steal private information, what attack is being performed?
  • What email header field helps prevent sender address forgery?
  • Which tool simulates network types and technologies for analyzing the impacts on end-to-end behaviors?
  • Which PsLoggedOn parameter prevents showing logon times while displaying user details?
  • Which tool retrieves detailed information about the process that opened a specific port?
  • What set of techniques do attackers use to hinder forensic investigations?
  • Which element of an email header helps safeguard senders and recipients from phishing, spoofing, and spamming?
  • Which version of the FAT file system employs 4 bytes per cluster in the file allocation table?
  • Which command can help determine whether the Tor browser was used on the suspected machine?
  • What does the function of a boot loader in NTFS systems primarily include?
  • Which type of cybercrime uses unsanitized input vulnerabilities to access a target database?
  • Which of the following layers of the Internet is the visible part of the web, where contents are indexed by search engines such as Google, Yahoo, and Bing?
  • What does the result "Received-SPF: Neutral" in an email exchange indicate?
  • What crime is demonstrated when a person's credentials are stolen through a fake shopping website?
  • Which functionality of Autopsy extracts web history and bookmarks from browsers?
  • What does a SMTP server do in the context of email communication?
  • During which phase is data preservation critical to ensure evidentiary integrity?
  • Which attack exploits vulnerabilities in a web application to execute unauthorized commands?
  • Which netstat parameter displays the active TCP connections and retrieves the process ID for each connection?
  • Which of the following describes what an Areal density measures?
  • In an Apache access log entry, which status code indicates a successful response?
  • What is the first activity in the sequence of the computer forensics investigation methodology?
  • What device did Grayson use to authenticate user access for evidence retrieval?
  • Which parameter in the Autorunsc command indicates that the scan should include user-specific settings?
  • What is the mandatory requirement for every tool used in the disk imaging process?
  • What is one of the main functions of a mail transfer agent?
  • What is a key aspect of reporting findings in digital forensics?
  • What type of attack involves flooding a switch's interface with Ethernet frames from fake hardware addresses?
  • What phase involves setting up a computer forensics lab and obtaining approval from relevant authorities?
  • Which of the following practices is considered detrimental for a computer forensics investigator?
  • What is the correct sequence of the first three steps in the data acquisition methodology?
  • What type of system did Cyril use to lure attackers and gather information about them?
  • Which approach helps forensic officers correlate specific packets with others and recognize potential network attacks?
  • What type of attack involves an employee exploiting their access to gain confidential data?
  • What tool did Steve, the professional hacker, use to maintain persistence and hide malicious traces?
  • Which part of the forensics investigation report contains investigative techniques used during the investigation?
  • What crime involves attackers harassing individuals or groups through emails or instant messages?
  • In which FHS directory would Gavin likely find mount points for unauthorized removable storage devices?
  • What information in the superblock of ext2 indicates whether a full file system check is necessary?
  • Which step in the search and seizure process involves obtaining consent and witness signatures?
  • In the netstat command, which parameter is used to display all active TCP connections on which the computer is listening?
  • In social engineering, what term describes a technique used to mislead a victim into providing sensitive data?
  • What log details does a honeypot machine provide when an attacker connects to it?
  • When collecting evidence, what is crucial to ensure its admissibility in court?
  • What is the type of web application threat demonstrated by hijacking a user's credentials to impersonate them?
  • What rule of evidence requires clarity and comprehensibility in presenting evidence to a jury?
  • Which SWGDE standards insist that all activities related to digital evidence must be documented?
  • Which time standard does the IIS server use to log timestamps in IIS logs?
  • Which type of attack forces an authenticated user to perform tasks on a web application chosen by the attacker?
  • Which role is responsible for the technical execution of forensic data analysis?
  • What does the term 'Enumeration' refer to in a security context?
  • What command retrieves the metadata of a file such as MAC times and file size?
  • What information is typically found in the "Investigation process" section of a forensics investigation report?
  • What is a common characteristic of an ad-hoc connection attack?
  • What does the data acquisition tool need to do before any response or data collection?
  • Which component of NTFS acts as a boot loader and accesses the boot.ini file?
  • Which of the following is NOT a characteristic of the Surface web?
  • Identify the administrative statute under HIPAA that mandates standard national numbers for employers.
  • What is the purpose of establishing a legal advisory board during forensic readiness planning?
  • What does the seek time characteristic of a hard disk represent?
  • Which section of an email contains the sender's contact information?
  • What information does the ID section of a sector contain?
  • Which component of an SSD serves as a bridge between the flash memory and the system?
  • Which mnemonic in Cisco IOS logs indicates a packet matching the log criteria for a given access list?
  • Which technique is used for performing dynamic analysis in a testbed for malware?
  • What is the primary activity involved in the evidence preservation phase?
  • Which component of EFS uses CryptoAPI to encode the File Encryption Key (FEK)?
  • Which of the following tasks is the responsibility of a forensic investigator?
  • What method did Arnold use to retrieve all deleted files and folders from suspected media while preventing contamination of the original media?
  • What numeric code indicates an error condition message in Cisco IOS router logs?
  • Which tool did Peyton employ to collect information about open TCP and UDP ports?
  • Which information does the routing table provide regarding a network?
  • Which command does Eduardo use to collect detailed network information, including session information and network packets?
  • In the context of malware analysis, what is the purpose of using a sandbox environment?
  • Which investigation phase involves the analysis of evidence and compilation of findings?
  • What is The Sleuth Kit?
  • Which type of evidence may require stricter procedures for preservation due to its volatile nature?
  • Which part of the forensic data acquisition methodology involves validating the acquisition?
  • What format of data encryption is used by the middle Tor relay?
  • Which command would provide information on the active connections and ports in use on a suspected machine?
  • Which method involves dismantling an executable into binary format to study its functionalities?
  • Which activity is the last step in the computer forensics investigation methodology?
  • Which type of log entry indicates the date and time of the request in Apache logs?
  • Which unique identifier, generated by the Windows OS, is 128 bits long and identifies specific devices or documents?
  • What is the correct order of steps to retrieve an email header from Microsoft Outlook?
  • Which aspect of a computer system is often examined to determine the timeline of events during an investigation?
  • In terms of computer platforms, what is a desirable quality for a computer forensics investigator?
  • What is the primary goal of mail bombing?
  • Before investigating a cybercrime, what phase involves setting up the forensics lab and developing an investigation toolkit?
  • What step in the data acquisition methodology involves enabling write protection on the evidence media?
  • What is the advanced correlation approach that predicts an attacker's next move based on statistics?
  • What aspect of malware analysis does malware disassembly primarily focus on?
  • Identify the Tor relay used for data transmission in an encrypted format, receiving the client's data from the entry relay, and passing the client's data to the exit relay.
  • In the scenario where a hacker sends a malicious email link leading to backdoor access, what type of attack is illustrated?
  • Which type of attack was performed by Bruce using a radio transmitter to block Wi-Fi access temporarily?
  • Identify the cmdlet used by Bryson to analyze the GUID partition table in the given hard disk scenario.
  • What does postmortem analysis in a network refer to?
  • Which tool can recover deleted email messages depending on how soon the recovery is attempted?
  • Which step ensures that collected evidence is securely stored according to policy?
  • Which command helps forensic investigators retrieve information about all active processes and open files?
  • From which type of device did Asher retrieve evidence?
  • What command might be used to close a specific file shared by a user?
  • What kind of attack did Kasen perform against the company's web server that involved flooding it with traffic?
  • In a Check Point firewall, which color code indicates suspicious traffic that is accepted?
  • What is the correct sequence of steps in forensic readiness planning?
  • Which component of the Apache core is responsible for handling data exchange and socket connections between clients and servers?
  • Where are the logs on a Linux system that record details about running services typically located?
  • What tool is mainly used to inspect, edit files, and recover lost data from hard drives?
  • Which file system was developed by Apple to replace the Macintosh File System?
  • Which tasklist parameter specifies the types of process(es) to include or exclude in the main query?
  • Which standard for sanitizing target media involves a wiping method that writes zeros in the first pass and random bytes in the next?
  • Which rule of evidence requires that investigators provide supporting documents about the legitimacy of evidence?
  • Which command will help Eduardo retrieve the NetBIOS name-to-IP address mappings?
  • What role does an expert witness play in a forensics investigation team?
  • Which of the following steps refers to acquiring data that is stored and not being used at the moment?
  • Which of the following measures helps security professionals defend against anti-forensics techniques?
  • During which phase does the investigator photograph the computer monitor's screen?
  • What does event masking help avoid in a forensic investigation?
  • Which device did Aiden investigate that led to potential evidence related to unauthorized document transmission?
  • Which type of digital evidence is lost as soon as a computer system is powered off?
  • In the netstat command syntax, which parameter is used to display the contents of the IP routing table?
  • Which parameter in the PsLoggedOn command provides information about users currently logged-on to the local system?
  • What is the maximum data storage unit typically allocated to a file smaller than the cluster size?
  • What is the purpose of creating a chain of custody in a forensic investigation?
  • What term describes the act of repeatedly sending emails to overload a specific address?
  • What does the mnemonic %SEC-2-WARNING in Cisco IOS logs signify?
  • Which method is typically used for gathering data from an active computer system?
  • Which part of the Apache core manages server startups and timeouts?
  • Which type of attack was performed by Alexis when he used a specially designed transmitter to disrupt access for legitimate clients?
  • What is the purpose of data carving in digital forensics?
  • Which title of the ECPA relates to the privacy of subscriber records held by service providers?
  • What is the purpose of the '-a' parameter in the nbtstat command?
  • Which layer of the TCP/IP model selects the best path for data flow between the source and destination?
  • Which hacker technique is specifically targeted at high-level executives or influential individuals?
  • What type of attack uses a method to overload access points and deny service to legitimate users?
  • What type of evidence is primarily collected by forensic investigators?
  • What component of email communication routes messages from the sender to their destination?
  • Which sequence accurately represents the steps involved in the email investigation process?
  • What netstat command allows forensic investigators to view the list of network interfaces on a system?
  • Which command will Kaison use to retrieve metadata of a malicious file?
  • What measure is defined as the number of bits that can fit per square inch on a hard disk platter?
  • What type of information requires a constant power supply to remain intact?
  • What specific files did Gael extract to find information about the incident related to fake email broadcasting?
  • In research, which log files would likely contain details about failed login attempts on a Linux system?
  • Identify the web that forms the topmost layer and stores content that can be accessed as well as indexed by search engines such as Google, Yahoo, and Bing.
  • Which term describes the technique used by Renit to collect information like network topology and potential vulnerabilities?
  • What functionality of Autopsy is used to recover deleted files from unallocated space?
  • Which SWGDE standard emphasizes the need for agencies to maintain written technical procedures?
  • Which field in the IIS log entry indicates that the user requested to download a file?
  • In the scenario where an attacker sends spam emails with a .PPSX attachment and malware executes upon mouse hovering, what technique is used to distribute malware?
  • What command is used to display information about all logged-in sessions of the local computer without parameters?
  • What type of files did Jayden suspect might contain useful information from a powered-off system?
  • What command checks the Linux kernel version on a system?
  • Which type of network attack requires the attacker to have physical access to the network?
  • Which step in the email process ensures the integrity of the email content?
  • Which of the following skills is crucial for analyzing digital evidence?
  • Which AFF4 object stores segments that are indivisible blocks of data?
  • Which type of network attack manipulates data packets exchanged between a client and server?
  • Which phase is Xavier in when he documents all tasks performed to resolve the case?
  • What type of content is typically found in the "Supporting Files" section of a forensic investigation report?
  • What method assists users in determining if a system serves as a relay to a hacker?
  • Which PsLoggedOn parameter helps retrieve the details of locally logged-in users?
  • What type of malware distribution involves embedding malicious software in an advertisement?
  • Which type of cybercrime involves stealing trade secrets or copyright material?
  • What type of attack involves tricking users into providing their confidential information?
  • What does the '-e' parameter do in the netstat command syntax?
  • Which of the following is a digital forensic artifact that helps investigators detect security incidents on a host system?
  • What is the term for the process of extracting data from storage media without altering it?
  • From which device did Calvin retrieve evidence that includes usage logs and network identity information?
  • What type of activity is cyber defamation categorized as?
  • Which command-line tool is utilized for investigating disk images in digital forensics?
  • What type of data does static acquisition primarily target?
  • At which point is a forensic investigator required to follow legal protocols to secure evidence?
  • What is the correct sequence of steps involved in the dead acquisition process?
  • What technique refers to missing events related to systems downstream from a failed system?
  • What is a critical aspect of the step 'Keep an incident response team ready'?
  • Which functionality does Autopsy employ to analyze and recover web cookies?
  • What command can be used to monitor real-time network connections in Linux?
  • Which of the following commands helps investigators retrieve important information such as the MAC times of any file and timestamps of applications in a Mac system?
  • In the scenario where Aziel's device connected to an attacker-installed hotspot after a power outage, what type of attack is depicted?
  • Which command can be used to monitor failed login attempts on an FTP server using a display filter?
  • In the context of network security, which action is categorized as eavesdropping?
  • What does the step 'Determine the sources of evidence' aim to achieve in forensic readiness planning?
  • In a forensic team, who is responsible for accumulating information from involved parties?
  • In an email crime investigation, what is the next step after seizing the computer and email accounts?
  • Which result in an email exchange indicates a possibility of unauthorized IP addresses sending emails on behalf of the domain?
  • Which parameter in the Autorunsc command syntax specifies printing output as tab-delimited values?
  • Which characteristic is common to all forensics tools used for packet analysis?
  • In which directory of the Filesystem Hierarchy Standard did a forensic expert identify binary files?
  • What is an open-source tool, written in Perl, for extracting and parsing information from the registry?
  • What allows users to receive emails in conjunction with other email communication components?
  • What is considered a best practice when dealing with email security?
  • Which of the following can be extracted as web artifacts by Autopsy?
  • What is a primary goal of anti-forensics from the perspective of an attacker?
  • Which command is used to display disk space usage for file systems in Linux?
  • Identify the packet sniffing tool that allows forensic specialists to browse live network data packets interactively.
  • What is the first phase of the UEFI boot process?
  • What is the purpose of sanitizing the target media in the data acquisition process?
  • Which type of memory is volatile, requires power to retain data, and is included in an SSD for improved performance?
  • Which PsList parameter displays processes, memory information, and threads?
  • What is the severity level of the syslog message with code 0 on the Cisco router?
  • Which tool did Kylo use to identify open ports on a target system?
  • Which attack is characterized by sending multiple requests to a server to exhaust its resources?
  • What role did Easton play in the forensics investigation team?
  • What type of attack did Don perform on Johana's email account to steal her files?
  • What is a primary objective of the post-investigation phase?
  • What is the primary function of the controller in an SSD?
  • Which of the following identifies the coding language often used for web application scripting that attackers target?
  • What is a PCIe SSD best described as?
  • What is the term for the wasted area in a disk cluster that occurs when a file is smaller than the cluster size?
  • Which of the following is a program that conceals the malicious code of malware, making it difficult for security mechanisms to detect it?
  • Which structure of the HFS volume keeps track of allocations of blocks in use and those that are free?
  • In an email message header, where must one add a recipient's email address?
  • What does a sector on a hard disk drive typically store?
  • Where are printer logs located on a Linux system?
  • What is a key purpose of using GUIDs in the context of operating systems?
  • Identify the data acquisition format that involves creating a bit-by-bit copy of the suspected drive using the dd command.
  • Which automated tool did a forensic expert employ to analyze deleted files from a Windows system?
  • What phase is Austin performing when he secures devices affected during an attack?
  • What is the social engineering technique that involves executing malicious software on a victim's computer?
  • Which of the following Tor relays is treated as suspected because it is perceived to be the origin of malicious traffic?
  • What role did Robert take during the investigation of the system attack?
  • What severity level is indicated by syslog code 3?
  • Which tool displays basic information about running processes, including the running time in kernel and user modes?
  • Which of the following artifacts can help investigators explore the Tor browser when it is uninstalled from a machine or installed in a location other than the Windows desktop?
  • Which attack method uses deceptive websites to capture personal credentials?
  • Which forensic readiness planning step focuses on defining evidence collection purposes?
  • Which file contains information about user accounts and passwords in Linux?
  • Which evidence source contains the least volatile data?
  • What is the purpose of using IIS logs in digital forensics?
  • Which parameter in the netstat command displays all active TCP connections as well as the TCP and UDP ports on which the computer is listening?
  • Which sector content is key for ensuring a smooth data read process?
  • How many total steps are involved in the data acquisition methodology?
  • In which phase does Bruno maintain a logbook and create a chain of custody record?
  • Which of the following log files in a Mac system contains information related to network interface history?
  • Which of the following is the default Mac application that helps retrieve specific files and folders and sort them in the required order?
  • What is the smallest physical storage unit on a hard-disk platter known as?
  • In the FAT32 file system, what is the maximum number of clusters?
  • What is a key consideration for investigators when creating a testbed for malware analysis?
  • Which act was passed by the U.S. Congress in 2002 to protect investors from fraudulent accounting activities?
  • Which data acquisition method failed for George when trying to create a bit-by-bit copy of an old suspect drive?
  • What does PCI DSS stand for in relation to information security standards?
  • Which characteristic defines the time it takes for a disk controller to find specific data?
  • What cybercrime was committed by James when he downloaded a malicious appointment letter?
  • What command did Zayn execute to view TCP and UDP network connections on a Windows machine?
  • Which component of a hard disk drive sector provides time for the controller to continue the read process?
  • What command would Kayden most likely have executed to create a backup and restore the MBR from a Linux machine?
  • Which type of data is classified as the most volatile, persisting only for nanoseconds?
  • What does the tool Dependency Walker do within an executable file?
  • Which NTFS system file contains definitions for all system and user-defined attributes of the volume?
  • Which evidence type can be regarded as indirect evidence in a digital forensics context?
  • In IIS log entries, which "sc-status" code indicates that a request was fulfilled successfully?
  • Which of the following parameters in the Autorunsc command syntax specifies the LSA security providers to scan?
  • What phase of the forensics investigation process involves reporting and documenting all actions and findings?
  • What command did Joselyn execute to extract the login history and system boot time?
  • Which type of disk interface allows personal computers to communicate with peripheral hardware?
  • Which of the following data acquisition methods did Tyler perform in the scenario of investigating a crime scene and inspecting a specific portion of the drive?
  • What type of attack is characterized by an employee manipulating internal systems to harm the organization?
  • What is one key aspect of a man-in-the-middle attack?
  • What type of crime is typically associated with stealing someone's identity to commit fraud?
  • What is one primary focus of the GLBA?
  • Which command is typically used in Linux to clone data from one storage device to another?
  • What tool did Eliana, a forensics expert, use to activate screen recording of criminal evidence?
  • Which component of email communication is used for reading, sending, and organizing emails?
  • What is the main goal of using an automated scan during a forensic investigation for malware?
  • What term refers to portions of a hard drive that may contain data from previously deleted files or unused space?
  • What is the open-source data acquisition format that offers an alternative to proprietary formats by storing disk images and related metadata?
  • What malware distribution technique exploits flaws in browser software to install malware upon visiting a web page?
  • Which data type provides a summary of network traffic conversations?
  • What is the primary purpose of using a forensic imaging tool?
  • What kind of attack did Henry launch to obtain users' credentials?
  • What is a password hash?
  • Which command is used for viewing the active connections on a computer system?
  • What data acquisition method did Hudson initiate while investigating a running computer?
  • What type of attack involves a harmful program that can control a system and cause damage?
  • Which of the following is usually a common characteristic of malware?
  • Which component of EFS is responsible for user access to encrypted files?
  • Which of the following tasks may require the expertise of a computer forensics investigator in a legal context?
  • Which consideration involves maintaining a log register at the entrance of a lab?
  • Which of the following identifies a sector on a disk?
  • What type of data did Serin utilize to summarize conversations between two network devices?
  • What type of attack did Jack perform against his organization's database server?
  • Which practice is NOT considered a countermeasure against anti-forensic techniques?
  • What quality is essential for a successful computer forensics investigator?
  • Which user-created evidence source can help investigators analyze malicious links?
  • Which parameter is NOT a part of the netstat command to show statistics?
  • Which section of a forensics investigation report includes the tools and techniques used for collecting evidence?
  • What does the dash "-" in an IIS log entry signify in terms of user identity?
  • What type of data did Williams recover from the powered-off victim system?
  • In the command executed by Eduardo, which parameter troubleshoots NetBIOS name resolution problems?
  • What is the name of the tool for assessing IT configurations and reporting change activity across IT infrastructure?
  • Which command can provide information about the status of a mounted filesystem in Linux?
  • Identify the Tor relay that receives the client's data from the middle relay and sends the data to the destination website's server.
  • What is the smallest physical storage unit on a hard disk drive called?
  • From which evidence source did Waylon collect data that persists even when the system is shut down?
  • What does the term 'Sector' refer to in data storage terminology?
  • In which phase does a forensic officer perform data acquisition and analysis of evidentiary data?
  • What is the primary role of the logical block in HFS file systems?
  • Where did Jayce discover essential device files on the Linux system with an FHS file system?
  • Which command is used to collect information about files opened by an intruder using remote login?
  • What security risk is often associated with exit relays in Tor networks?
  • What type of attack did Moises utilize when he compelled an employee to attach a malicious USB to gain access to confidential data?
  • In the context of digital forensics, what is the main purpose of tools like Autorunsc?
  • What law was enacted in 1999 to mandate financial institutions to safeguard sensitive data?
  • Which NTFS system file stores metadata for all files, including malicious events?
  • In the scenario where Reid manipulated the communication of a COVID survey website, what type of attack did he conduct?
  • What type of attack did Stetson commit when he secretly installed a sniffing device to listen to conversations on a network?
  • Which data acquisition format was designed by Cohen, Garfinkel, and Schatz to support large capacity storage media?
  • Which social engineering technique redirects victims' traffic to malicious websites controlled by attackers?
  • What type of attack did Benjamin conduct after gaining trust within the organization?
  • What advantage does a forensically ready incident response team provide to an organization?
  • Which role involves providing legal advice in a forensic investigation?
  • What cybercrime primarily aims to harm an organization's reputation?
  • What is the primary outcome of performing a MAC flooding attack on a switch?
  • Which utility would Ryder use to check for bad sectors and lost clusters on a FAT file system in Windows?
  • Who is considered the main legal authority in a forensic investigation?
  • Which command would you use to display all running services in a Linux environment?
  • What tool can the system administrator use to view active TCP and UDP connections in the system?
  • Which nbtstat parameter allows viewing the contents of the NetBIOS name cache?
  • Which SWGDE standard requires agencies to use appropriate hardware and software for evidence procedures?
  • What evidence rule is demonstrated when John submitted evidence without any intermediary tampering?
  • What type of attack did Malcolm perform by using stolen credentials to intrude into an organization's network?
  • Which task is NOT a responsibility of a forensic investigator?
  • What is the primary purpose of the PsList tool?
  • What does the AFF4 object that includes collections of RDF statements serve as?
  • During which phase did Lincoln create a report and document all actions performed?
  • When discussing network attacks, what is a common goal of jamming attacks?
  • What type of phishing attack targets high-profile individuals such as CFOs to extract valuable information?
  • Which tasklist parameter lists all service information for each process without truncation?
  • Which of the following is NOT a function of a mail user agent?
  • Which of the following describes the nature of the honeypot employed by Cyril?
  • What type of cybercrime did Medicing Inc. engage in by hiring a hacker to steal product information?
  • What command would Harrison use to view the detailed partition layout for a GPT disk and MBR details in Windows?
  • Which netstat parameter displays all active TCP connections as well as UDP ports the computer is listening on?
  • Which port is used by the njRAT Trojan?
  • What is the primary function of the Finder application on a Mac system?
  • What type of attack involves capturing traffic flowing through a network to obtain sensitive information?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy