Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 2

Windows Memory and Artifact Analysis DFE Practice Questions (Page 5)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
9concepts

Questions 21–25

  1. 21application · medium

    An investigator is examining a Windows 10 system and needs to find evidence of user logon activity. Which Windows artifact should be examined?

    Select an answer first
  2. 22foundation · easy

    Which Windows artifact is used to speed up application startup and can indicate program execution history?

    Select an answer first
  3. 23application · medium

    An examiner has a memory dump and a disk image from a Windows system. The examiner wants to build a comprehensive timeline of system activity, including process execution, network connections, and logon events. Which approach would best correlate these data sources?

    Select an answer first
  4. 24application · medium

    An investigator is reconstructing a user's activities on a Windows 10 machine. The user is suspected of opening a confidential document from a network share and then browsing a specific website. Which artifacts would provide the most direct evidence of these actions?

    Select an answer first
  5. 25foundation · easy

    In Volatility, which plugin is used to list active processes from a memory dump?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.