
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 1
Windows Forensics CHFI Practice Questions (Page 4)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
59questions here
12free pages
18concepts
Questions 16–20
- 16
A forensic examiner is investigating a case where a user allegedly viewed images on a Windows 10 system. The original images were deleted, but the examiner wants to find evidence of the images being viewed. Which artifact would be most useful?
Select an answer first - 17
A forensic examiner is investigating a case involving illicit images on a Windows 10 system. The images were deleted, but the examiner wants to recover thumbnails that may have been generated when the images were viewed. Which file should the examiner look for?
Select an answer first - 18
Where are the Recycle Bin files ($I and $R) stored on a Windows system?
Select an answer first - 19
What is the primary forensic value of thumbnail cache files (thumbcache_*.db) on a Windows system?
Select an answer first - 20
A forensic analyst is investigating a case where a user allegedly accessed a sensitive document on a network share. The analyst found a .lnk file in the user's Recent Items folder. What information from the LNK file would help confirm the document was accessed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.