Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 3Objective 1

Windows Forensics CHFI Practice Questions (Page 5)

Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.

59questions here
12free pages
18concepts

Questions 21–25

  1. 21application · medium

    A user deleted a confidential document from an NTFS volume and emptied the Recycle Bin. The examiner needs to recover the original file path and the deletion time. Which approach is most likely to yield this information?

    Select an answer first
  2. 22foundation · easy

    Which of the following is a common location where LNK files are found on a Windows system?

    Select an answer first
  3. 23foundation · easy

    Which NTFS timestamp is most likely to change when a file is merely read or opened?

    Select an answer first
  4. 24foundation · easy

    Which Windows artifact is specifically used to optimize application startup and can provide evidence of when an application was last run?

    Select an answer first
  5. 25foundation · easy

    Which component of the NTFS file system is a special file that contains metadata about every file and directory on the volume?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.