
EC-CouncilDigital Forensics Essentials
Domain 4Objective 1
Windows Volatile and Non-Volatile Data Collection DFE Practice Questions (Page 5)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
8concepts
Questions 21–25
- 21
What is the primary purpose of computing hash values (e.g., MD5 or SHA-256) during evidence collection?
Select an answer first - 22
Which of the following Windows artifacts is considered non-volatile data?
Select an answer first - 23
An incident responder is collecting volatile data from a Windows system and needs to capture the current clipboard contents, which may contain sensitive information. Which tool is designed for this purpose?
Select an answer first - 24
An incident responder is performing live response on a Windows server. The responder has a limited time window before the system must be rebooted for business continuity. Which sequence of volatile data collection best follows the order of volatility?
Select an answer first - 25
Which of the following is an example of volatile data that a forensic investigator should collect from a live Windows system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.