
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 1
Windows Forensics CHFI Practice Questions (Page 8)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
59questions here
12free pages
18concepts
Questions 36–40
- 36
Which Windows Event ID is commonly associated with a successful logon event in the Security log?
Select an answer first - 37
A forensic examiner is investigating a system where a user deleted a critical file and then ran a disk cleanup utility. The examiner wants to recover the file's previous content. Which method is most likely to succeed?
Select an answer first - 38
Which Windows artifact maps IP addresses to MAC addresses on the local network and can reveal recent network communications?
Select an answer first - 39
On an NTFS volume, where does a deleted file's data typically reside until it is overwritten?
Select an answer first - 40
Which Windows artifact is specifically designed to speed up application startup by storing information about the files and data loaded by an executable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.