
EC-CouncilDigital Forensics Essentials
Domain 4Objective 1
Windows Volatile and Non-Volatile Data Collection DFE Practice Questions (Page 7)
Part of the Operating System Forensics domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
8concepts
Questions 31–35
- 31
In which scenario is live response more appropriate than static acquisition?
Select an answer first - 32
During a live response, an investigator collects volatile data and then performs a static acquisition. To maintain a proper chain of custody, which documentation step is essential?
Select an answer first - 33
During a Windows forensic investigation, which of the following is classified as volatile data?
Select an answer first - 34
An examiner is analyzing a forensic image of a Windows system and needs to extract the user's recently accessed files and typed URLs from the registry. Which tool is specifically designed for this task?
Select an answer first - 35
An investigator is performing static acquisition on a seized Windows laptop. The investigator needs to extract user activity artifacts such as recently accessed files and typed URLs, along with system configuration data, without booting the suspect drive. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.