Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

EC-Council Digital Forensics Essentials (DFE)

Last Update 17 hours ago Total Questions : 75

The EC-Council Digital Forensics Essentials (DFE) content is now fully updated, with all current exam questions added 17 hours ago. Deciding to include 112-57 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 112-57 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 112-57 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any EC-Council Digital Forensics Essentials (DFE) practice test comfortably within the allotted time.

Question # 1

Which of the following hives in the Windows Registry hierarchical database is volatile in nature and contains file-extension association information and programmatic identifier (ProgID), Class ID (CLSID), and Interface ID (IID) data?

A.

HKEY_LOCAL_MACHINE

B.

HKEY_CURRENT_USER

C.

HKEY_CURRENT_CONFIG

D.

HKEY_CLASSES_ROOT

Question # 2

Jennifer, a forensics investigation team member, was inspecting a compromised system. After gathering all the evidence related to the compromised system, she disconnected the system from the network to stop the spread of the incident to other systems.

Identify the role played by Jennifer in the forensics investigation.

A.

Incident responder

B.

Incident analyzer

C.

Evidence manager

D.

Expert witness

Question # 3

Williams, a forensic specialist, was tasked with performing a static malware analysis on a suspect system in an organization. For this purpose, Williams used an automated tool to perform a string search and saved all the identified strings in a text file. After analyzing the strings, he determined all the harmful actions that were performed by malware.

Identify the tool employed by Williams in the above scenario.

A.

R-Drive Image

B.

ResourcesExtract

C.

Ezvid

D.

Snagit

Question # 4

James, a forensic specialist, was appointed to investigate an incident in an organization. As part of the investigation, James is attempting to identify whether any external storage devices are connected to the internal systems. For this purpose, he employed a utility to capture the list of all devices connected to the local machine and removed suspicious devices.

Identify the tool employed by James in the above scenario.

A.

ESEDatabaseView

B.

ProcDump

C.

DriveLetterView

D.

PromiscDetect

Question # 5

Clark, a security professional, identified that one of the systems in the organization is infected with malware and was used for creating a backdoor. Clark employed an automated tool to analyze the system's memory and detect malicious activities performed on the system.

In the above scenario, which of the following tools did Clark employ to detect malicious activities performed on the system?

A.

Medusa

B.

Redline

C.

Shodan

D.

Wireshark

Question # 6

Which of the following tools helps a forensics investigator develop and test across multiple operating systems in a virtual machine for Mac and allows access to Microsoft Office for Windows?

A.

Riverbed Modeler

B.

Parallels Desktop 16

C.

Camtasia

D.

NetSim

Question # 7

Below are the elements included in the order of volatility for a typical computing system as per the RFC 3227 guidelines for evidence collection and archiving.

Archival media

Remote logging and monitoring data related to the target system

Routing table, process table, kernel statistics, and memory

Registers and processor cache

Physical configuration and network topology

Disk or other storage media

Temporary system files

Identify the correct sequence of order of volatility from the most to least volatile for a typical system.

A.

7-- > 5-- > 4-- > 3-- > 2-- > 6-- > 1

B.

4-- > 3-- > 7-- > 6-- > 2-- > 5-- > 1

C.

2-- > 1-- > 4-- > 3-- > 6-- > 5-- > 7

D.

4-- > 3-- > 7-- > 1-- > 2-- > 5-- > 6

Question # 8

Below are the various steps involved in an email crime investigation.

1.Acquiring the email data

2.Analyzing email headers

3.Examining email messages

4.Recovering deleted email messages

5.Seizing the computer and email accounts

6.Retrieving email headers

What is the correct sequence of steps involved in the investigation of an email crime?

A.

5-- > 1-- > 3-- > 6-- > 2-- > 4

B.

2-- > 4-- > 3-- > 6-- > 5-- > 1

C.

1-- > 3-- > 6-- > 4-- > 5-- > 2

D.

1-- > 3-- > 4-- > 2-- > 5-- > 6

Question # 9

Below is the syntax of a command-line utility that displays active TCP connections and ports on which the computer is listening.

netstat [-a] [-e] [-n] [-o] [-p Protocol] [-r] [-s] [Interval]

Identify the netstat parameter that displays active TCP connections and includes the process ID (PID) for each connection.

A.

[-n]

B.

[-a]

C.

[-o]

D.

[-s]

Question # 10

Which of the following standards and criteria version of SWGDE mandates that any action with the potential to alter, damage, or destroy any aspect of original evidence must be performed by qualified persons in a forensically sound manner?

A.

Standards and Criteria 1.3

B.

Standards and Criteria 1.7

C.

Standards and Criteria 1.5

D.

Standards and Criteria 1.1

Go to page: