Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 2

Windows Memory and Artifact Analysis DFE Practice Questions (Page 10)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
9concepts

Questions 46–50

  1. 46application · medium

    An analyst has a memory dump from a Windows system and needs to extract the list of network connections that were active at the time of acquisition. Which Volatility plugin should be used?

    Select an answer first
  2. 47foundation · easy

    Which file system artifact contains the master file table (MFT) on an NTFS volume?

    Select an answer first
  3. 48foundation · easy

    Which of the following is a common method to acquire volatile memory from a Windows system?

    Select an answer first
  4. 49foundation · easy

    Which Windows artifact is used to recover files that were deleted by the user?

    Select an answer first
  5. 50expert · hard

    An investigator is analyzing a Windows system and finds that the Prefetch folder is empty. The investigator suspects that a specific program was executed. Which artifact could provide evidence of execution despite the empty Prefetch folder?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to DFE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.