
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 1
Windows Forensics CHFI Practice Questions (Page 6)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
59questions here
12free pages
18concepts
Questions 26–30
- 26
A forensic examiner is analyzing an NTFS volume and needs to recover a deleted file that was stored in an alternate data stream (ADS). The examiner has identified the MFT entry for the file, but the ADS data is not visible in the normal file listing. Which approach should the examiner take to recover the ADS data?
Select an answer first - 27
A forensic examiner is responding to a live incident on a Windows 10 system. The examiner needs to capture volatile data that would be lost when the system is powered off. Which data should be captured FIRST?
Select an answer first - 28
Which registry hive contains the Security Account Manager (SAM) database that stores local user account credentials?
Select an answer first - 29
A forensic analyst is investigating a Windows 10 system that was used to access a malicious website. The analyst needs to determine the IP address that the system resolved for the domain name. Which artifact should the analyst examine?
Select an answer first - 30
Which Windows artifact records the execution of programs from the GUI and is stored in the Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.