Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 1

Windows Volatile and Non-Volatile Data Collection DFE Practice Questions (Page 2)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

39questions here
8free pages
8concepts

Questions 6–10

  1. 6application · medium

    An investigator is documenting the collection of volatile data from a Windows system. To ensure the evidence is admissible in court, which piece of information is most critical to record?

    Select an answer first
  2. 7foundation · easy

    Which of the following is an example of non-volatile data that can be collected from a Windows system for forensic analysis?

    Select an answer first
  3. 8application · medium

    An investigator is triaging a Windows system that is suspected of being compromised. The investigator wants to capture data that will be lost if the system is rebooted. Which of the following should be collected FIRST?

    Select an answer first
  4. 9foundation · easy

    Which of the following is a volatile data item that should be captured during live response on a Windows system?

    Select an answer first
  5. 10expert · hard

    A forensic investigator is responding to a suspected data exfiltration incident on a Windows server. The server is running and the investigator must decide whether to perform a live response or a static acquisition. The server is also a domain controller with active user sessions. Which factor is MOST important in deciding to perform a live response first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.