Windows Operating System Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Windows Operating System Forensics flashcards as text
Which Windows artifact stores the last 10 commands typed into the Run dialog box and is found in the registry?
Answer: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
The RunMRU key stores the most recently used commands typed into the Run dialog, useful for tracking attacker activity.
A forensic investigator needs to determine which USB devices were ever connected to a Windows system. Which registry key is the primary source?
Answer: HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR
HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR logs all USB storage devices ever connected, including vendor and product IDs.
Which Windows log file records successful and failed logon attempts and is critical for investigating unauthorized access?
Answer: Security.evtx
Security.evtx contains event IDs 4624 (successful logon) and 4625 (failed logon), making it the primary source for access investigations.
What is the purpose of the $MFT file in NTFS forensics?
Answer: It is the Master File Table containing metadata for every file and directory on the volume
The $MFT (Master File Table) is the core NTFS structure storing file name, size, timestamps, and data location for every file.
A Windows system was shut down abruptly. Which file can help a forensic investigator recover the contents of RAM at the time of shutdown?
Answer: hiberfil.sys
hiberfil.sys stores a compressed image of RAM when the system hibernates, allowing recovery of memory contents including running processes and open files.
Which Windows artifact records the applications that were set to auto-start at system boot and can reveal persistence mechanisms used by malware?
Answer: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The Run key under both HKLM and HKCU is a common persistence location where programs are registered to execute automatically at every user login.
In Windows forensics, what does the acronym LNK file refer to and why is it forensically significant?
Answer: A Windows shortcut file that records metadata about accessed files including original path and timestamps
LNK (shortcut) files automatically created in Recent Items contain metadata about accessed files including MAC times, file size, and original volume serial number.