CHFI OS and Network Forensics • Set 3
CHFI OS and Network Forensics Practice Test 3 — 15 questions with explanations. Free, no signup.
During a Windows forensic investigation, an analyst finds a registry key under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count. What type of artifact is this, and what information does it typically contain?