CHFI • Practice Test 29
Free CHFI practice test — 15 questions with explanations. Set 29. No signup required.
A forensic analyst is investigating a compromised Linux server running an ext4 file system. The analyst suspects the attacker deleted critical log files (e.g., /var/log/auth.log) and wants to recover them. Which TWO techniques would be MOST effective for recovering the deleted files?