
EC-CouncilCertified Security Specialist
Domain 6Objective 1
Windows Forensics ECSS Practice Questions (Page 3)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
39questions here
8free pages
10concepts
Questions 11–15
- 11
Which forensic tool is commonly used to create a forensic image of a Windows drive and supports the Expert Witness Format (EWF)?
Select an answer first - 12
In Windows Event Log analysis, what is the primary purpose of the System log?
Select an answer first - 13
During a live incident response, an analyst must decide whether to capture memory first or image the disk first. The system is a domain controller with active user sessions. Which approach is most defensible?
Select an answer first - 14
A Windows workstation is suspected of being used to access malicious websites. Which Windows artifact would provide the most direct evidence of the user's browsing activity?
Select an answer first - 15
An investigator is examining a Windows 10 workstation to determine which applications a user launched during a specific time window. The system has been powered off and a forensic image was taken. Which artifact would be most useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.