Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 3Objective 1

Windows Forensics CHFI Practice Questions (Page 12)

Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.

59questions here
12free pages
18concepts

Questions 56–59

  1. 56application · medium

    During an investigation, an examiner finds a .lnk file on a user's desktop that points to a document on a network share. The examiner wants to determine when the document was last accessed and the name of the machine that hosted the share. Which information can be extracted from the LNK file?

    Select an answer first
  2. 57application · medium

    An examiner is analyzing a Windows 10 system to determine which user accounts were used to log on and whether any accounts were recently created. Which registry hives should be examined to obtain this information?

    Select an answer first
  3. 58foundation · easy

    Which Windows artifact is a registry key that tracks the execution of programs and is also known as the Application Compatibility Cache?

    Select an answer first
  4. 59application · medium

    A forensic examiner needs to acquire a forensic image of a Windows 10 system's hard drive. The system is running and the examiner wants to minimize changes to the system. Which acquisition method is most appropriate?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CHFI

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.