
EC-CouncilDigital Forensics Essentials
Domain 4Objective 2
Windows Memory and Artifact Analysis DFE Practice Questions (Page 7)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
9concepts
Questions 31–35
- 31
An analyst is examining a memory dump from a Windows 10 machine. The analyst suspects that a malware process is hiding its network connections by using a rootkit. The analyst also needs to determine if the malware modified the registry to achieve persistence. Which Volatility plugins should the analyst use in combination to confirm both the hidden network connections and the registry modification?
Select an answer first - 32
What is the primary purpose of Windows event logs in forensic analysis?
Select an answer first - 33
A forensic investigator is called to a scene where a Windows system is running and the suspect is still logged in. The investigator needs to preserve evidence of the current state of the system, including running processes and network connections. Which tool should be used to acquire this volatile data?
Select an answer first - 34
A forensic examiner is analyzing a Windows 10 system and needs to determine which user accounts were created recently, what programs were installed, and whether any files were deleted from the system drive. Which combination of artifact locations should the examiner prioritize?
Select an answer first - 35
An analyst is investigating a user's activity on a Windows system and needs to determine which documents the user opened. Which user activity artifact should be examined?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.