
EC-CouncilDigital Forensics Essentials
Domain 4Objective 2
Windows Memory and Artifact Analysis DFE Practice Questions (Page 5)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
9concepts
Questions 21–25
- 21
An investigator is examining a Windows 10 system and needs to find evidence of user logon activity. Which Windows artifact should be examined?
Select an answer first - 22
Which Windows artifact is used to speed up application startup and can indicate program execution history?
Select an answer first - 23
An examiner has a memory dump and a disk image from a Windows system. The examiner wants to build a comprehensive timeline of system activity, including process execution, network connections, and logon events. Which approach would best correlate these data sources?
Select an answer first - 24
An investigator is reconstructing a user's activities on a Windows 10 machine. The user is suspected of opening a confidential document from a network share and then browsing a specific website. Which artifacts would provide the most direct evidence of these actions?
Select an answer first - 25
In Volatility, which plugin is used to list active processes from a memory dump?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.