Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 3Objective 1

Windows Forensics CHFI Practice Questions (Page 3)

Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.

59questions here
12free pages
18concepts

Questions 11–15

  1. 11application · medium

    A forensic examiner is reconstructing a timeline of user activity on a Windows 10 system. The examiner has found Prefetch files, Shimcache, and UserAssist entries. Which artifact would provide the most reliable chronological order of program executions?

    Select an answer first
  2. 12foundation · easy

    What is the purpose of constructing a timeline in Windows forensics?

    Select an answer first
  3. 13foundation · easy

    In NTFS, what does the 'M' in MAC times stand for?

    Select an answer first
  4. 14application · medium

    An examiner is investigating a Windows system that was used to connect to a malicious server. The examiner wants to identify the IP address of the server from the system's network activity. Which artifact should be examined first?

    Select an answer first
  5. 15application · medium

    A forensic examiner is analyzing a Windows 10 system to determine whether a user viewed a specific image file that has since been deleted. Which artifact is most likely to contain a preview of the image?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.