
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 1
Windows Forensics CHFI Practice Questions (Page 10)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
59questions here
12free pages
18concepts
Questions 46–50
- 46
A forensic examiner is responding to an incident on a Windows 10 system. The system is still running, and the examiner needs to capture volatile data, including running processes and network connections. The examiner also needs to preserve the system's memory for later analysis. Which action should be taken first?
Select an answer first - 47
What is the primary purpose of an alternate data stream (ADS) in NTFS?
Select an answer first - 48
A forensic examiner is analyzing a FAT32 formatted USB drive and needs to recover a deleted file. The file was deleted recently, and the examiner has a forensic image of the drive. Which technique is most likely to recover the file?
Select an answer first - 49
A forensic examiner is analyzing a Windows 10 system and needs to determine which applications were run on the system, including the last execution time. Which artifact would provide the most comprehensive list of executed applications?
Select an answer first - 50
Which Windows Registry hive contains information about the currently logged-on user's settings, including environment variables and desktop configuration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.