Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 4Objective 1

Windows Volatile and Non-Volatile Data Collection DFE Practice Questions (Page 6)

Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.

39questions here
8free pages
8concepts

Questions 26–30

  1. 26expert · hard

    A forensic investigator is collecting volatile data from a Windows system and must ensure the evidence is admissible in court. The investigator has collected the output of netstat, tasklist, and openfiles. Which additional step is critical to maintain the chain of custody?

    Select an answer first
  2. 27foundation · easy

    Which Windows command-line tool is used to display the list of running processes for volatile data collection?

    Select an answer first
  3. 28application · medium

    An incident responder is called to a scene where a Windows workstation is still running. The responder must decide which data to collect first. Which item is the MOST volatile and should be collected first?

    Select an answer first
  4. 29application · medium

    A forensic investigator is called to respond to a suspected malware infection on a Windows 10 workstation that is still powered on. The investigator must preserve the maximum amount of evidence. Which action should be performed first?

    Select an answer first
  5. 30foundation · easy

    Which of the following is a non-volatile Windows artifact that can provide evidence of user activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.