
EC-CouncilDigital Forensics Essentials
Domain 4Objective 2
Windows Memory and Artifact Analysis DFE Practice Questions (Page 1)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
9concepts
Questions 1–5
- 1
A security analyst is investigating a Windows system that was compromised. The analyst has access to the Security event log and needs to determine if an attacker used a valid user account to log on remotely. Which event ID and logon type should be examined?
Select an answer first - 2
Which tool is commonly used to analyze Windows memory dumps and extract process, network, and registry information?
Select an answer first - 3
An investigator is analyzing a Windows registry hive to determine which USB devices were connected to a workstation. Which registry key should be examined?
Select an answer first - 4
An analyst is examining a memory dump from a Windows 10 system. The analyst suspects that a malware process is using a technique to hide its executable from the file system, and also that it modified the registry to disable Windows Defender. Which Volatility plugins would be most effective in confirming both the hidden process and the registry modification?
Select an answer first - 5
What does a Prefetch file primarily indicate to a forensic examiner?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.