
EC-CouncilCertified Security Specialist
Domain 6Objective 1
Windows Forensics ECSS Practice Questions (Page 2)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
39questions here
8free pages
10concepts
Questions 6–10
- 6
What is the primary purpose of using a write blocker when creating a forensic image of a Windows system?
Select an answer first - 7
During a forensic examination of a Windows 10 system, an analyst needs to identify which file system feature is most relevant for recovering the original file name of a deleted file that has been moved to a different directory. Which NTFS structure should the analyst examine?
Select an answer first - 8
A forensic responder arrives at a scene where a Windows system is running. The responder needs to capture volatile data that would be lost upon shutdown. Which action should be performed first?
Select an answer first - 9
A forensic responder is called to a scene where a Windows system is running and the suspect is actively using it. The responder needs to preserve volatile evidence while minimizing disruption. Which action should be taken first?
Select an answer first - 10
Which Windows artifact is most useful for determining which files a user recently opened from the File Explorer interface?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.