Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 2

Windows Memory and Artifact Analysis DFE Practice Questions (Page 4)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
9concepts

Questions 16–20

  1. 16foundation · easy

    Which of the following is an example of correlating memory and disk artifacts?

    Select an answer first
  2. 17foundation · easy

    Which registry key is commonly used to determine programs that run at system startup?

    Select an answer first
  3. 18expert · hard

    An investigator is analyzing a Windows system to reconstruct a user's activities. The investigator has access to the user's NTUSER.DAT hive and the Recent folder. Which combination of artifacts would provide the most comprehensive evidence of the user's actions?

    Select an answer first
  4. 19foundation · easy

    Which Windows event log is most likely to contain records of successful and failed logon attempts?

    Select an answer first
  5. 20foundation · easy

    Which registry hive contains information about the currently logged-in user's settings and activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.