
EC-CouncilComputer Hacking Forensic Investigator
Domain 3Objective 1
Windows Forensics CHFI Practice Questions (Page 9)
Part of the Operating System Forensics domain, which makes up ~12% of our current practice bank.
59questions here
12free pages
18concepts
Questions 41–45
- 41
A forensic examiner is analyzing a Windows 10 system and needs to determine which USB devices were connected to the system. Which registry hive and key should the examiner examine?
Select an answer first - 42
Which of the following is a widely used commercial forensic tool that can acquire and analyze Windows systems?
Select an answer first - 43
What is the primary purpose of using a write blocker during forensic acquisition?
Select an answer first - 44
What is the file extension of the modern Windows Event Log format introduced in Windows Vista and later?
Select an answer first - 45
Which Windows artifact records information about USB devices that have been connected to the system, including the device serial number and last connection time?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.