
EC-CouncilDigital Forensics Essentials
Domain 4Objective 2
Windows Memory and Artifact Analysis DFE Practice Questions (Page 8)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
9concepts
Questions 36–40
- 36
A forensic examiner is analyzing a Windows 10 system where a user deleted a sensitive PDF file from the Desktop and emptied the Recycle Bin. The examiner needs to recover evidence of the file's existence and possibly its content. Which file system artifact should the examiner examine first?
Select an answer first - 37
A forensic investigator arrives at a Windows 10 workstation that is suspected of running a credential-stealing process. The machine is currently powered on and the user is logged in. The investigator must preserve the highest-fidelity volatile evidence before any further system interaction. Which action should be taken first?
Select an answer first - 38
A forensic examiner needs to recover a deleted file from a Windows NTFS volume. The file was recently deleted and the system has been powered off. Which file system artifact should be examined first?
Select an answer first - 39
An incident response team is analyzing a Windows server that was compromised. They have a memory dump and a disk image. The team needs to determine the exact sequence of events: when the attacker first connected, what process was used for the attack, and when a backdoor account was created. Which approach would provide the most comprehensive timeline?
Select an answer first - 40
What is Shimcache (AppCompatCache) used for in Windows forensics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.