
EC-CouncilCertified Security Specialist
Domain 6Objective 1
Windows Forensics ECSS Practice Questions (Page 7)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
39questions here
8free pages
10concepts
Questions 31–35
- 31
A forensic analyst is examining a Windows 10 system and needs to extract the user's recent activities, including files opened and programs run. Which tool is best suited for this task?
Select an answer first - 32
An investigator needs to create a forensic image of a suspect's Windows laptop hard drive. Which procedure best ensures data integrity and admissibility?
Select an answer first - 33
An investigator needs to recover deleted files from a Windows 10 system and also verify the integrity of the evidence. Which tool combination is most appropriate?
Select an answer first - 34
A security analyst is investigating a potential intrusion on a Windows server. The analyst notices that the Security event log is missing events between 2:00 AM and 3:00 AM. Which action should the analyst take to determine if the log was cleared?
Select an answer first - 35
Which Windows event log is specifically designed to record security-related events such as logon attempts, account management, and object access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.