Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 3Objective 1

Windows Forensics CHFI Practice Questions (Page 11)

Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.

59questions here
12free pages
18concepts

Questions 51–55

  1. 51expert · hard

    An examiner is investigating a user's activity on a Windows 10 system. The user is suspected of viewing inappropriate images and searching for related content. The examiner has access to the thumbnail cache, the Windows Search index, and the user's browser history. Which combination of artifacts would provide the most comprehensive evidence of the user's activity?

    Select an answer first
  2. 52foundation · easy

    Which Windows command-line utility can be used to display the DNS resolver cache, which contains recently resolved domain names?

    Select an answer first
  3. 53expert · hard

    A security analyst is investigating a Windows 10 system that was compromised. The analyst has access to the Security event log, but the log is missing events from a specific time period. The analyst suspects that an attacker deleted the events. Which approach is most likely to recover the missing events?

    Select an answer first
  4. 54foundation · easy

    What is the primary reason for capturing a memory image in Windows forensics?

    Select an answer first
  5. 55foundation · easy

    Which of the following artifacts is specifically used to track GUI-based program launches and is stored in the Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.