
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 1
Windows Forensics CHFI Practice Questions (Page 3)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
59questions here
12free pages
18concepts
Questions 11–15
- 11
A forensic examiner is reconstructing a timeline of user activity on a Windows 10 system. The examiner has found Prefetch files, Shimcache, and UserAssist entries. Which artifact would provide the most reliable chronological order of program executions?
Select an answer first - 12
What is the purpose of constructing a timeline in Windows forensics?
Select an answer first - 13
In NTFS, what does the 'M' in MAC times stand for?
Select an answer first - 14
An examiner is investigating a Windows system that was used to connect to a malicious server. The examiner wants to identify the IP address of the server from the system's network activity. Which artifact should be examined first?
Select an answer first - 15
A forensic examiner is analyzing a Windows 10 system to determine whether a user viewed a specific image file that has since been deleted. Which artifact is most likely to contain a preview of the image?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.