
EC-CouncilDigital Forensics Essentials
Domain 4Objective 1
Windows Volatile and Non-Volatile Data Collection DFE Practice Questions (Page 1)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
8concepts
Questions 1–5
- 1
An investigator needs to collect non-volatile data from a Windows system that is already shut down. The investigator wants to preserve the original evidence without modification. Which tool is appropriate for creating a forensic image of the hard drive?
Select an answer first - 2
What is the primary difference between live response and static acquisition in Windows forensics?
Select an answer first - 3
An investigator is examining a Windows system that was shut down after a suspected data exfiltration. The investigator needs to recover the last accessed URLs and search terms from the user's web browser. Which non-volatile data source should be examined?
Select an answer first - 4
Which tool is specifically designed to parse and analyze Windows registry hives for forensic purposes?
Select an answer first - 5
A forensic investigator is collecting volatile data from a Windows server. To ensure the evidence is admissible in court, which documentation step is essential?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.