CHFI OS and Network Forensics • Set 7
CHFI OS and Network Forensics Practice Test 7 — 15 questions with explanations. Free, no signup.
During a forensic investigation of a Windows 10 system, an examiner finds the following registry key: NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count. The values contain Rot‑13 encoded data. What is the primary purpose of this artifact?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.