Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 1

Windows Forensics ECSS Practice Questions (Page 3)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

39questions here
8free pages
10concepts

Questions 11–15

  1. 11foundation · easy

    Which forensic tool is commonly used to create a forensic image of a Windows drive and supports the Expert Witness Format (EWF)?

    Select an answer first
  2. 12foundation · easy

    In Windows Event Log analysis, what is the primary purpose of the System log?

    Select an answer first
  3. 13expert · hard

    During a live incident response, an analyst must decide whether to capture memory first or image the disk first. The system is a domain controller with active user sessions. Which approach is most defensible?

    Select an answer first
  4. 14application · medium

    A Windows workstation is suspected of being used to access malicious websites. Which Windows artifact would provide the most direct evidence of the user's browsing activity?

    Select an answer first
  5. 15application · medium

    An investigator is examining a Windows 10 workstation to determine which applications a user launched during a specific time window. The system has been powered off and a forensic image was taken. Which artifact would be most useful?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.