
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 1
Windows Forensics CHFI Practice Questions (Page 1)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
59questions here
12free pages
18concepts
Questions 1–5
- 1
Which Windows feature relies on Volume Shadow Copies to allow users to restore previous versions of files?
Select an answer first - 2
An examiner is investigating a user's activity on a Windows 10 system. The user is suspected of searching for sensitive documents using the Windows Search feature. Which artifact should the examiner analyze to recover the search queries?
Select an answer first - 3
In the Windows Recycle Bin, which file type contains the original file's metadata, such as its original path and deletion timestamp?
Select an answer first - 4
An examiner is analyzing a file on an NTFS volume and notices that the file's last access time has been updated. The examiner wants to determine whether this update was caused by a user opening the file or by an automated process. Which factor is most important to consider?
Select an answer first - 5
Which of the following is an example of volatile data that can be extracted from a Windows memory image?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.