Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 2

Windows Memory and Artifact Analysis DFE Practice Questions (Page 3)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
9concepts

Questions 11–15

  1. 11expert · hard

    A forensic examiner is called to a Windows 10 machine that is suspected of running ransomware. The machine is on and the user is logged in. The examiner needs to acquire memory and also preserve the ability to correlate the memory dump with disk artifacts. The examiner has limited time and must choose the best order of actions. Which order is most appropriate?

    Select an answer first
  2. 12application · medium

    An examiner is investigating a Windows 10 system and needs to determine which executables were run from a temporary folder on a specific date. The system has prefetch enabled. Which artifact would provide the most direct evidence of these executions?

    Select an answer first
  3. 13application · medium

    An analyst has a memory dump from a compromised Windows server. The analyst suspects a specific process injected code into another process and made network connections to an external IP. Which Volatility command sequence would most directly confirm both the injection and the network connection?

    Select an answer first
  4. 14expert · hard

    An analyst is investigating a Windows 10 system where a user is suspected of running a specific portable tool that is not installed. The analyst has the disk image and needs to prove the tool was executed, even though the user may have deleted the executable. Which combination of registry and file system artifacts would provide the strongest evidence?

    Select an answer first
  5. 15expert · hard

    A forensic examiner is investigating a case where a user deleted a sensitive file from a Windows NTFS volume. The system has been powered off since the deletion. The examiner needs to recover the file content. Which approach is most likely to succeed?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.