Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 1

Windows Volatile and Non-Volatile Data Collection DFE Practice Questions (Page 1)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

39questions here
8free pages
8concepts

Questions 1–5

  1. 1application · medium

    An investigator needs to collect non-volatile data from a Windows system that is already shut down. The investigator wants to preserve the original evidence without modification. Which tool is appropriate for creating a forensic image of the hard drive?

    Select an answer first
  2. 2foundation · easy

    What is the primary difference between live response and static acquisition in Windows forensics?

    Select an answer first
  3. 3application · medium

    An investigator is examining a Windows system that was shut down after a suspected data exfiltration. The investigator needs to recover the last accessed URLs and search terms from the user's web browser. Which non-volatile data source should be examined?

    Select an answer first
  4. 4foundation · easy

    Which tool is specifically designed to parse and analyze Windows registry hives for forensic purposes?

    Select an answer first
  5. 5application · medium

    A forensic investigator is collecting volatile data from a Windows server. To ensure the evidence is admissible in court, which documentation step is essential?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.