Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 3Objective 1

Windows Forensics CHFI Practice Questions (Page 9)

Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.

59questions here
12free pages
18concepts

Questions 41–45

  1. 41application · medium

    A forensic examiner is analyzing a Windows 10 system and needs to determine which USB devices were connected to the system. Which registry hive and key should the examiner examine?

    Select an answer first
  2. 42foundation · easy

    Which of the following is a widely used commercial forensic tool that can acquire and analyze Windows systems?

    Select an answer first
  3. 43foundation · easy

    What is the primary purpose of using a write blocker during forensic acquisition?

    Select an answer first
  4. 44foundation · easy

    What is the file extension of the modern Windows Event Log format introduced in Windows Vista and later?

    Select an answer first
  5. 45foundation · easy

    Which Windows artifact records information about USB devices that have been connected to the system, including the device serial number and last connection time?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.