
EC-CouncilCertified Security Specialist
Domain 6Objective 1
Windows Forensics ECSS Practice Questions (Page 6)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
39questions here
8free pages
10concepts
Questions 26–30
- 26
Why is volatile memory analysis critical in Windows forensics?
Select an answer first - 27
During a live incident response, an analyst must capture evidence that would be lost if the system were powered off. Which type of data should be collected first?
Select an answer first - 28
A forensic analyst is investigating a case of unauthorized software installation. The analyst needs to determine which programs were installed on a Windows 10 system and when. Which registry hive and key should be examined?
Select an answer first - 29
A forensic examiner is analyzing a Windows 10 system that has both NTFS and FAT32 partitions. The examiner needs to recover a deleted file from the FAT32 partition. Which challenge is most likely to be encountered?
Select an answer first - 30
During a forensic examination of an NTFS volume, an analyst needs to determine when a specific file was first created on the system. Which timestamp should be examined?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.