Windows Forensics

Windows Forensics

University

10 Qs

quiz-placeholder

Similar activities

Ch 10 Windows Installation Quiz

Ch 10 Windows Installation Quiz

University

14 Qs

OS Quiz week 3

OS Quiz week 3

University

12 Qs

Backup, Restore, and Recovery

Backup, Restore, and Recovery

9th Grade - University

7 Qs

Windows 10-Disk Managment

Windows 10-Disk Managment

9th Grade - University

11 Qs

AZ-900 Modulo 2

AZ-900 Modulo 2

KG - Professional Development

14 Qs

Windows 10 System Management  Tools

Windows 10 System Management Tools

9th Grade - University

10 Qs

Chapter 8 Review

Chapter 8 Review

University

10 Qs

Backup Files

Backup Files

9th Grade - University

15 Qs

Windows Forensics

Windows Forensics

Assessment

Quiz

Computers

University

Hard

Created by

dono pradana

Used 1+ times

FREE Resource

10 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

What does the netstat command with the -ano options display?

Network information

Open files on the system

Process information

Dump File

2.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which tool can be used to examine the contents of an ESE database file?

ESEDatabaseView

DumpChk

DriveLetterView

Process Dumper

3.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

What is the purpose of examining Windows crash dumps in forensic investigation?

To diagnose and identify bugs in a program

To collect information about network connections

To extract data from the Windows registry

To determine the system uptime

4.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which command can be used to dump the memory of a process?

PsLoggedOn

netstat

adplus.vbs

Userdump.exe

5.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

What is the purpose of collecting slack space in forensic investigation?

To determine the system uptime

To identify the logged-on users

To locate open files on the system

To retrieve data from previously deleted files

6.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which tool can be used to examine the contents of a Windows search index?

ESEDatabaseView

DumpChk

DriveLetterView

Process Dumper

7.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which tool can be used to analyze RAM dumps?

Belkasoft RAM Capturer

AccessData FTK Imager

Redline

Hex Workshop

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?