Windows Operating System Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Windows Operating System Forensics flashcards as text
A CHFI investigator is analyzing a Windows system and wants to identify all network connections that were active at the time of a memory dump. Which command-line tool output should be examined in the memory image?
Answer: netstat -ano
Netstat -ano output captured in memory shows all active TCP/UDP connections, their PIDs, and listening ports at the exact time of acquisition.
Which Windows artifact contains evidence of files that were recently printed, including document name, printer used, and timestamp?
Answer: C:\Windows\System32\spool\PRINTERS\
The Windows print spooler folder stores EMF and SHD spool files for print jobs, including document metadata and timing, until the job completes.
In NTFS, which metadata file records changes to the file system including file creation, modification, and deletion, and is essential for timeline analysis?
Answer: $UsnJrnl:$J
The NTFS Change Journal ($UsnJrnl:$J) records file system changes with USN (Update Sequence Number) entries, enabling chronological reconstruction of file activity.
What does Windows event ID 4688 record and why is it forensically valuable?
Answer: A new process was created, including the process name and parent process
Event ID 4688 logs process creation events with executable path and parent PID, enabling investigators to reconstruct attacker command execution chains.
An investigator recovers a Windows system where the attacker cleared the Security event log. Which artifact may still contain evidence of the log clearing action?
Answer: The System event log — event ID 104
Event ID 104 in the System log records when the Security log was cleared, and event ID 1102 in the Security log records the same action if any entries remain.
Which Windows registry key stores the time zone setting of the system, which is critical for accurate timeline normalization during forensic analysis?
Answer: HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation
The TimeZoneInformation key stores the active time zone bias values used by Windows, essential for converting system timestamps to UTC for accurate correlation.
A forensic investigator discovers shellbags in the Windows registry. What specific user activity do shellbags record?
Answer: Folder view preferences and evidence that a user opened specific folders, including on removed external drives
Shellbags store folder view settings and prove a user opened specific directories, even revealing folder names from devices no longer connected to the system.