
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 1
Windows Forensics CHFI Practice Questions (Page 5)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
59questions here
12free pages
18concepts
Questions 21–25
- 21
A user deleted a confidential document from an NTFS volume and emptied the Recycle Bin. The examiner needs to recover the original file path and the deletion time. Which approach is most likely to yield this information?
Select an answer first - 22
Which of the following is a common location where LNK files are found on a Windows system?
Select an answer first - 23
Which NTFS timestamp is most likely to change when a file is merely read or opened?
Select an answer first - 24
Which Windows artifact is specifically used to optimize application startup and can provide evidence of when an application was last run?
Select an answer first - 25
Which component of the NTFS file system is a special file that contains metadata about every file and directory on the volume?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.