
EC-CouncilDigital Forensics Essentials
Domain 4Objective 1
Windows Volatile and Non-Volatile Data Collection DFE Practice Questions (Page 4)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
8concepts
Questions 16–20
- 16
A forensic investigator is collecting volatile data from a Windows 10 system. The investigator needs to capture the list of running processes along with their parent process IDs to analyze process relationships. Which tool or command is most appropriate?
Select an answer first - 17
Why is it important to record the version of the tool used during evidence collection?
Select an answer first - 18
A forensic examiner needs to collect event logs from a Windows system that is currently running. The examiner wants to preserve the logs in a format that can be analyzed later without altering the original system. Which method is most appropriate?
Select an answer first - 19
During a live response on a Windows system, an investigator captures a memory dump and then runs netstat -ano. The investigator notices a suspicious connection to an external IP. To correlate this connection with a specific process, which additional volatile data should the investigator collect?
Select an answer first - 20
A forensic examiner is analyzing a Windows system image and needs to determine which user accounts were recently logged on and what programs they executed. The examiner has access to the registry hives and event logs. Which combination of non-volatile data sources is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.