Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 1

Windows Forensics ECSS Practice Questions (Page 6)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

39questions here
8free pages
10concepts

Questions 26–30

  1. 26foundation · easy

    Why is volatile memory analysis critical in Windows forensics?

    Select an answer first
  2. 27application · medium

    During a live incident response, an analyst must capture evidence that would be lost if the system were powered off. Which type of data should be collected first?

    Select an answer first
  3. 28application · medium

    A forensic analyst is investigating a case of unauthorized software installation. The analyst needs to determine which programs were installed on a Windows 10 system and when. Which registry hive and key should be examined?

    Select an answer first
  4. 29expert · hard

    A forensic examiner is analyzing a Windows 10 system that has both NTFS and FAT32 partitions. The examiner needs to recover a deleted file from the FAT32 partition. Which challenge is most likely to be encountered?

    Select an answer first
  5. 30application · medium

    During a forensic examination of an NTFS volume, an analyst needs to determine when a specific file was first created on the system. Which timestamp should be examined?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.