
EC-CouncilDigital Forensics Essentials
Domain 4Objective 2
Windows Memory and Artifact Analysis DFE Practice Questions (Page 9)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
50questions here
10free pages
9concepts
Questions 41–45
- 41
During a forensic examination of a Windows 10 system, an investigator needs to find evidence of a user's recently accessed files and the programs they launched. Which combination of Windows artifacts should be examined?
Select an answer first - 42
An examiner is investigating a Windows system where an attacker is suspected of creating a local user account and then deleting it. The examiner has a disk image and needs to determine the account name and the exact time it was created. Which combination of artifacts would provide the most reliable evidence?
Select an answer first - 43
An investigator is analyzing a Windows 10 system where a user is suspected of accessing a specific file on a USB drive and then browsing a specific website. The user claims they never used the USB drive. The investigator finds LNK files in Recent Items that reference the USB drive's file, but the USB drive is not connected. Which additional artifact would best corroborate that the USB drive was connected?
Select an answer first - 44
A security analyst is reviewing Windows event logs to identify failed logon attempts. Which event ID should be examined?
Select an answer first - 45
A security analyst is reviewing a Windows event log to determine if an attacker successfully logged into a domain account from a remote workstation at 2:00 AM. Which event log and event ID should the analyst focus on?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.