Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 1

Windows Volatile and Non-Volatile Data Collection DFE Practice Questions (Page 5)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

39questions here
8free pages
8concepts

Questions 21–25

  1. 21foundation · easy

    What is the primary purpose of computing hash values (e.g., MD5 or SHA-256) during evidence collection?

    Select an answer first
  2. 22foundation · easy

    Which of the following Windows artifacts is considered non-volatile data?

    Select an answer first
  3. 23application · medium

    An incident responder is collecting volatile data from a Windows system and needs to capture the current clipboard contents, which may contain sensitive information. Which tool is designed for this purpose?

    Select an answer first
  4. 24application · medium

    An incident responder is performing live response on a Windows server. The responder has a limited time window before the system must be rebooted for business continuity. Which sequence of volatile data collection best follows the order of volatility?

    Select an answer first
  5. 25foundation · easy

    Which of the following is an example of volatile data that a forensic investigator should collect from a live Windows system?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.