Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 2

Windows Memory and Artifact Analysis DFE Practice Questions (Page 6)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

50questions here
10free pages
9concepts

Questions 26–30

  1. 26foundation · easy

    Where are Windows event logs typically stored?

    Select an answer first
  2. 27application · medium

    An examiner is investigating a Windows machine where a user allegedly ran a portable application from a USB drive. The application does not appear in the installed programs list. Which registry hive and key should the examiner examine to find evidence of the USB device and the application's execution?

    Select an answer first
  3. 28foundation · easy

    Why is memory forensics important in a Windows investigation?

    Select an answer first
  4. 29foundation · easy

    Which of the following is a user-specific artifact that can reveal a user's web browsing history?

    Select an answer first
  5. 30foundation · easy

    Which user activity artifact is created when a user opens a document or file from Windows Explorer?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.