Windows Operating System Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Windows Operating System Forensics flashcards as text
Which Windows artifact can reveal evidence of a program execution even if the executable has since been deleted, by tracking compatibility telemetry data?
Answer: Application Compatibility Cache (Shimcache) in the registry
The Shimcache (AppCompatCache) registry key tracks executables that the Windows Application Compatibility engine has processed, persisting evidence of execution even after deletion.
A CHFI examiner wants to determine the exact time a specific user last logged into a Windows workstation interactively. Which is the most reliable forensic source?
Answer: Security event log event ID 4624 with Logon Type 2 or 10
Event ID 4624 with Logon Type 2 (interactive) or Type 10 (remote interactive/RDP) provides the precise timestamp and workstation name for each user logon.
What forensic information can be extracted from Windows Jump Lists located in AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations?
Answer: Recently and frequently accessed files per application, including files on removed media
Jump Lists store per-application MRU entries (AppIDs) linking recently opened files, revealing what an application accessed even after files are deleted.
During a ransomware investigation on a Windows system, which registry artifact would help determine if the Volume Shadow Copies were deleted by the attacker?
Answer: System event log combined with examining vssadmin.exe in the Shimcache or Amcache
Checking Shimcache/Amcache for vssadmin.exe or wmic.exe execution, combined with System log entries, reveals whether shadow copies were deliberately purged.
What is the Amcache.hve file and how does it differ from Shimcache in Windows forensics?
Answer: Amcache is a registry hive storing SHA1 hashes and install/execution metadata; Shimcache stores execution timestamps without hashes
Amcache.hve stores executable metadata including SHA1 file hash, enabling identification of specific malware binaries, while Shimcache tracks execution without storing hashes.
A Windows forensic investigation reveals the presence of a file named 'NTUSER.DAT.LOG1'. What is the forensic significance of this file?
Answer: It is a transaction log for the NTUSER.DAT registry hive that may contain uncommitted registry changes
NTUSER.DAT.LOG1 and .LOG2 are registry transaction logs that buffer pending writes; they may contain registry data not yet flushed to the main hive file.
Which Windows forensic artifact stores evidence of files that were deleted via the Windows GUI (dragged to Recycle Bin) including original file path and deletion time?
Answer: $Recycle.Bin\$I files on the volume root
$I files in $Recycle.Bin store the original file path, file size, and deletion timestamp for each deleted item, while $R files hold the actual deleted content.