
EC-CouncilDigital Forensics Essentials
Domain 4Objective 2
Windows Memory and Artifact Analysis DFE Practice Questions (Page 10)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
9concepts
Questions 46–50
- 46
An analyst has a memory dump from a Windows system and needs to extract the list of network connections that were active at the time of acquisition. Which Volatility plugin should be used?
Select an answer first - 47
Which file system artifact contains the master file table (MFT) on an NTFS volume?
Select an answer first - 48
Which of the following is a common method to acquire volatile memory from a Windows system?
Select an answer first - 49
Which Windows artifact is used to recover files that were deleted by the user?
Select an answer first - 50
An investigator is analyzing a Windows system and finds that the Prefetch folder is empty. The investigator suspects that a specific program was executed. Which artifact could provide evidence of execution despite the empty Prefetch folder?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.