Courseiva

CCNA Windows Artifact Analysis Questions

28 questions · Windows Artifact Analysis · All types, answers revealed

1
MCQeasy

An analyst is reviewing a Windows 10 system and wants to determine the last time a user accessed a specific file. The analyst examines the file's NTFS standard information attributes and finds that the last access time is not updated. What is the most likely reason for this?

A.NTFS last access time updates are disabled by default.
B.The file has the 'N' attribute set.
C.The file system is mounted as read-only.
D.The file is on a network share.
AnswerA

Windows disables last access time updates by default to improve performance. This behavior is controlled by the registry value NtfsDisableLastAccessUpdate, which is set to 1 by default in modern Windows versions. Therefore, the last access time is not updated when files are accessed, explaining why the analyst sees no recent timestamp.

Why this answer

By default, Windows disables last access time updates to reduce disk I/O. The registry value NtfsDisableLastAccessUpdate controls this, and it is set to 1 on most modern systems. As a result, the last access time may not reflect recent file accesses, making it unreliable for forensic purposes unless the setting has been changed.

Exam trap

The trap here is assuming that last access time is always updated, when in fact it is disabled by default, leading analysts to draw incorrect conclusions about file access.

2
MCQmedium

An analyst is investigating a Windows 10 system where an attacker allegedly used a remote access tool (RAT) that persists by modifying the Image File Execution Options (IFEO) registry key. The analyst wants to identify which executable was hijacked. Which registry location should the analyst examine to find the Debugger value that redirects execution?

A.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
B.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
C.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache
AnswerA

Image File Execution Options (IFEO) is the correct registry location. Attackers can create a subkey named after a legitimate executable (e.g., notepad.exe) and set a Debugger string value pointing to their malicious binary. When the legitimate executable is launched, Windows starts the debugger instead, achieving persistence and execution. This matches the scenario.

Why this answer

IFEO hijacking involves creating a subkey under Image File Execution Options named after a legitimate executable and setting a Debugger value to a malicious program. This causes Windows to launch the debugger instead of the intended executable. The correct registry path is HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.

Other options are unrelated persistence or forensic artifacts.

Exam trap

The trap here is confusing IFEO with standard Run key persistence, which does not redirect execution of other processes.

3
MCQmedium

An analyst is examining a Windows 10 workstation that is suspected of having a malicious service installed for persistence. The analyst wants to determine the original path of the service executable and the account it runs under. Which registry location should the analyst examine to find this information?

A.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
B.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
C.HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
D.HKLM\SYSTEM\CurrentControlSet\Services
AnswerD

Each subkey under HKLM\SYSTEM\CurrentControlSet\Services represents an installed service and contains values such as ImagePath (the executable path) and ObjectName (the account the service runs under). This is the primary location for service configuration, making it the correct choice for identifying the original path and account.

Why this answer

The Services registry key stores configuration data for every Windows service, including the ImagePath value that points to the executable and the ObjectName value that specifies the account. Examining this key allows the analyst to identify the malicious service's original path and the security context it uses, which is critical for understanding persistence and privilege level.

Exam trap

The trap here is assuming that service information is stored in the Run key or other autostart locations, which are for user-level programs rather than system services.

4
MCQhard

An investigator is analyzing a Windows 10 system where an attacker allegedly used a PowerShell script to download and execute a malicious payload. The investigator wants to determine the exact PowerShell commands that were executed. Which Windows artifact should the investigator examine to find this information?

A.Windows Security Event Log
B.ConsoleHost_history.txt file
C.Prefetch files for PowerShell.exe
D.PowerShell Operational Event Log
AnswerD

The PowerShell Operational log (Microsoft-Windows-PowerShell/Operational) records detailed information about PowerShell execution, including script block logging (Event ID 4104) and engine state changes. If script block logging is enabled, the actual commands executed are captured, making this the correct artifact for determining the exact PowerShell commands used.

Why this answer

PowerShell Operational logging, when script block logging is enabled, captures the full content of scripts and commands executed, including those run by attackers. This makes it the most reliable artifact for reconstructing the exact PowerShell activity. Other artifacts like Prefetch or Security logs may show that PowerShell ran but not what it executed.

Exam trap

The trap here is assuming that any log showing PowerShell execution will contain the command details, when in fact only the PowerShell Operational log with script block logging enabled provides that level of detail.

5
MCQmedium

During a compromise investigation, an analyst reviews Windows Event Logs and observes that Security Event ID 4688 entries are present, but the Process Command Line field is empty for all of them. The system is running Windows 10 Enterprise. What is the most likely reason for the missing command line data?

A.The Security log has wrapped, and older entries containing command lines were overwritten before collection.
B.The 'Include command line in process creation events' policy under Administrative Templates\System\Audit Process Creation is not enabled.
C.The Windows Event Log service is configured to filter out command-line data for privacy reasons via a built-in security template.
D.Process creation auditing is not enabled at all, so Event ID 4688 should not appear.
AnswerB

This policy, when enabled, adds the full command line to the Process Creation event. Without it, Windows records the new process ID and image name but leaves the command line field blank. Enabling it requires a Group Policy update or registry change and is not on by default even when process creation auditing is active.

Why this answer

The correct answer is the policy that controls command-line inclusion in process creation events. When enabled, it populates the Process Command Line field in Event ID 4688. Without it, the field remains empty.

This is a common pitfall because process creation auditing alone does not guarantee command-line visibility; the separate policy must be turned on.

Exam trap

The trap here is assuming that enabling process creation auditing automatically records command lines, when a separate policy must also be enabled.

6
MCQmedium

An analyst is examining a Windows 10 system and finds a suspicious file in the Recycle Bin. The analyst wants to determine the original path of the file before it was deleted. Which artifact should the analyst examine to find the original file path and deletion time?

A.INFO2 file
B.$Recycle.Bin folder
C.$I file
D.$R file
AnswerC

The $I file is a metadata file created alongside the $R file (which contains the actual deleted data) when a file is deleted to the Recycle Bin. It stores the original file path, the deletion timestamp, and the file size. Examining the $I file provides the original path and deletion time, directly answering the analyst's question.

Why this answer

In Windows 10, each deleted file in the Recycle Bin has a corresponding $I file that stores the original path, deletion time, and file size. The $R file contains the actual data. The $Recycle.Bin folder is the container, and INFO2 is obsolete.

Therefore, the $I file is the correct artifact to examine.

Exam trap

The trap here is assuming that the $R file contains metadata, when in fact it only holds the file content, and the metadata is in the separate $I file.

7
Multi-Selectmedium

An analyst is examining a Windows 10 system to determine if a specific USB device was connected. The analyst has already checked the registry and found no trace in USBSTOR. Which TWO additional artifacts should the analyst examine to corroborate USB device connection? (Choose two.)

Select 2 answers
A.Prefetch files for USBSTOR.SYS
B.Registry key: HKLM\SYSTEM\CurrentControlSet\Enum\USB
C.Setupapi.dev.log
D.Windows Event Log: Microsoft-Windows-DriverFrameworks-UserMode/Operational
E.NTFS $MFT
AnswersC, D

Setupapi.dev.log records device installation and driver setup events, including USB devices. It can contain the device's vendor and product IDs, serial number, and timestamps of when the device was first connected. This makes it a valuable artifact for corroborating USB connection, especially when USBSTOR is cleared.

Why this answer

Setupapi.dev.log and the Microsoft-Windows-DriverFrameworks-UserMode/Operational event log both record USB device installation and connection events with timestamps and device identifiers. These artifacts can provide evidence of a USB device even if the USBSTOR registry key has been cleared, making them essential for corroboration.

Exam trap

The trap here is relying solely on the USBSTOR registry key, which can be cleared by anti-forensic tools or simply not present in some cases, while overlooking other logs that record device installation and connection.

8
MCQmedium

When analyzing the 'TypedPaths' registry key, what type of user activity is being reviewed?

A.Run dialog commands
B.Windows Explorer navigation paths
C.Recently opened documents
D.External device connection history
AnswerB

TypedPaths records the history of directory paths the user manually typed into the File Explorer address bar. This provides a direct record of the user's navigational intent, which is particularly useful for identifying access to sensitive directories that are not typically visible through standard menu-based browsing.

Why this answer

The 'TypedPaths' key is a goldmine for investigators as it stores the absolute paths that a user has manually entered into the Windows Explorer address bar. This artifact is highly reliable for proving user intent to access specific directories, including hidden folders or external media paths. By documenting where the user navigated, an analyst can build a compelling case regarding unauthorized file exploration that occurred outside of normal GUI clicking behavior.

Exam trap

Candidates often confuse TypedPaths with 'RecentDocs' or 'ShellBags', failing to distinguish that TypedPaths specifically records strings entered into the address bar, not just general folder access history.

9
MCQhard

An analyst is investigating a Windows 10 system and discovers that a user's NTUSER.DAT registry hive contains a key named 'RecentDocs' with numerous entries. What is the primary forensic significance of this artifact?

A.It stores the complete file path and SHA-256 hash of every document opened by the user.
B.It maintains a list of recently accessed files and folders, which can indicate user browsing activity and potential data exfiltration.
C.It records the most recently opened documents and folders, including the last access time and the application used to open them.
D.It tracks the execution time of applications associated with the opened documents.
AnswerB

RecentDocs keys under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs store lists of recently opened documents and folders, organized by file extension. They provide evidence of user activity, such as which files were accessed, and can help establish a timeline of user interactions. This is valuable for identifying potential data exfiltration or unauthorized access to sensitive files.

Why this answer

RecentDocs provides a list of recently accessed files and folders, which is valuable for understanding user activity and potential data exfiltration. It does not include hashes, execution times, or last access timestamps, so the correct interpretation is that it indicates browsing activity and accessed documents.

Exam trap

The trap here is assuming that RecentDocs contains timestamps or hashes, when it actually only lists recently accessed file and folder names, typically organized by extension.

10
MCQmedium

During a forensic examination of a Windows 10 workstation, an analyst needs to determine which user account was interactively logged on at a specific date and time. The system is powered off and only the disk image is available. Which artifact should the analyst examine to find the most reliable record of interactive logon sessions, including logon type and timestamp?

A.Prefetch files, checking the last execution time of explorer.exe
B.NTUSER.DAT registry hive, examining the LastWrite time of the user's shell bags
C.Security event log, filtering for Event ID 4624 with Logon Type 2 or 10
D.SRUM database, querying the Network Usage table for active connections
AnswerC

Event ID 4624 in the Security log records successful logons and includes the Logon Type field. Type 2 indicates interactive logon at the console, while Type 10 indicates RemoteInteractive (RDP). These events provide the account name, timestamp, and logon type, directly answering who was logged on interactively and when, assuming the log has not been cleared or overwritten.

Why this answer

Security event log entries with Event ID 4624 and Logon Type 2 or 10 provide definitive records of interactive and RemoteInteractive logons, including the account name, timestamp, and logon type. Other artifacts like shell bags, SRUM, or Prefetch may show user activity but lack the direct logon session details required to answer who was logged on and when.

Exam trap

The trap here is assuming that any user activity artifact, such as shell bags or Prefetch, can substitute for explicit logon event records when determining interactive logon sessions.

11
MCQeasy

A forensic analyst is examining a Windows 10 system and wants to determine which USB storage devices have been connected to the machine. The analyst has access to the registry. Which registry key should the analyst examine to find a list of USB devices that have been connected, including vendor and product IDs?

A.HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices
B.HKLM\SYSTEM\CurrentControlSet\Enum\USB
C.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
D.HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR\Enum
AnswerC

The USBSTOR key under Enum stores information about USB mass storage devices that have been connected to the system. Each subkey corresponds to a device and includes the vendor, product, and revision, as well as a serial number if available. This is the primary artifact for determining USB storage device connection history.

Why this answer

The USBSTOR registry key under HKLM\SYSTEM\CurrentControlSet\Enum is the authoritative location for USB mass storage device connection history. It records the vendor, product, and revision of each device, along with a serial number when available. Other USB-related keys either include non-storage devices or lack the detailed storage-specific information needed to identify connected USB drives.

Exam trap

The trap here is confusing the general USB enumeration key with the USBSTOR key, which is specifically for mass storage devices and contains the vendor and product details.

12
MCQmedium

Which artifact is the most reliable for determining if an external USB mass storage device was mounted on a system, even if the device is no longer present?

A.Prefetch files
B.USBSTOR Registry Key
C.ShellBags
D.SRUM (System Resource Usage Monitor)
AnswerB

The USBSTOR key in the SYSTEM hive acts as a central repository for all USB device connections. It stores the vendor, product ID, and serial number of the device. Even after the device is disconnected, this entry remains, providing a permanent record of the hardware's interaction with the system.

Why this answer

The 'USBSTOR' registry key in the SYSTEM hive is the definitive artifact for tracking USB device history. It records the vendor, model, and unique serial number of every USB device ever connected. This is critical for forensic investigations involving data exfiltration, as it allows the investigator to prove that a specific physical device was present, regardless of whether the user deleted the device drivers or emptied the recycle bin.

Exam trap

Candidates often look at the 'MountPoints2' key instead of 'USBSTOR', failing to realize that MountPoints2 is user-specific and can be cleared, whereas USBSTOR is system-wide and more persistent.

13
MCQmedium

An analyst discovers a suspicious executable in the C:\Users\Public folder. To determine if the file was executed, the analyst examines the Shimcache. Which behavior is characteristic of the Shimcache artifact?

A.It records the exact UTC execution time for all files in the SYSTEM hive.
B.Entries are only populated when the UserAssist key is enabled in the registry.
C.It tracks file path and last modification time for potential application compatibility.
D.It is stored within the NTUSER.DAT hive for each individual user profile.
AnswerC

Shimcache stores the file path and the last modified time of the executable. This helps the OS determine if a file is compatible. For forensics, this artifact is essential for identifying executable files that existed on the system, even if those files were subsequently deleted by an attacker.

Why this answer

The Shimcache, or AppCompatCache, tracks file metadata to ensure application compatibility. Crucially, it tracks file paths and last modified times but does not natively record the exact execution timestamp of an application. It is primarily used to identify files that were present on the system and potentially executed, serving as a critical indicator of software presence during an investigation into lateral movement or malware persistence on a Windows endpoint.

Exam trap

Candidates incorrectly believe the Shimcache provides a precise execution timestamp, leading them to misinterpret the 'Last Modified' file metadata as the moment the malicious file was run.

14
Multi-Selectmedium

An analyst is investigating a Windows 10 system for evidence of lateral movement. The analyst suspects that an attacker used PsExec to remotely execute commands on the system. Which TWO artifacts should the analyst examine to corroborate this activity? (Choose two.)

Select 2 answers
A.System event log for Event ID 7045 (service installation)
B.Prefetch files for PSEXESVC.exe
C.Amcache.hve for entries related to PsExec.exe
D.SRUM database for network connections by PsExec.exe
E.Security event log for Event ID 4624 with Logon Type 3
AnswersA, B

PsExec installs a temporary service named PSEXESVC on the target system. The installation of this service is recorded in the System event log with Event ID 7045, which includes the service name, image path, and service type. This provides strong evidence that PsExec was used, especially if the service name matches PSEXESVC.

Why this answer

PsExec usage on a target system leaves two key artifacts: the installation of the PSEXESVC service, recorded in the System event log as Event ID 7045, and the execution of PSEXESVC.exe, which generates a Prefetch file. These directly indicate PsExec activity. Other artifacts like network logons or Amcache entries are less specific and may be caused by other activities.

Exam trap

The trap here is focusing on generic network logon events or Amcache entries, which are not specific to PsExec, instead of the distinctive service installation and Prefetch artifacts that PsExec creates.

15
MCQmedium

Which registry hive contains the 'UserAssist' key, and what is its primary forensic value?

A.SYSTEM hive; tracking system services
B.NTUSER.DAT hive; tracking user-initiated program execution
C.SOFTWARE hive; tracking installed application paths
D.SECURITY hive; tracking authentication logs
AnswerB

UserAssist is located in the NTUSER.DAT hive, which is unique to each user profile on the system. It tracks the programs the user launches via the Windows shell, recording execution counts and timestamps, making it the primary artifact for identifying user-driven activity during an investigation.

Why this answer

UserAssist is stored within the NTUSER.DAT hive of the specific user account. Its value lies in the rotational cipher (ROT13) used for the data, which, once decrypted, reveals a list of GUI-based programs executed by the user. This artifact is invaluable for linking specific user activity to the execution of malicious tools, providing proof that the user was behind the keyboard during the incident, as opposed to an automated system service.

Exam trap

Candidates often confuse the UserAssist hive location with the SYSTEM hive or assume it tracks all system-wide background services, ignoring its specific focus on user-initiated GUI program execution.

16
MCQmedium

An analyst is investigating a Windows 10 system and finds a suspicious shortcut file in a user's Recent folder. The analyst wants to determine the full path of the target file and any command-line arguments used when the shortcut was created. Which artifact should the analyst examine?

A.The Windows Registry key: NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
B.The Prefetch file for explorer.exe
C.The jumplist AutomaticDestinations file
D.The .lnk file itself
AnswerD

The .lnk file (shortcut) contains a LinkTargetIDList and other structures that store the original target path, as well as command-line arguments if present. By parsing the .lnk file, the analyst can extract the full path and any arguments, making it the correct artifact for this purpose.

Why this answer

Shortcut (.lnk) files contain embedded structures that include the target path, working directory, command-line arguments, and other metadata. Parsing these files directly provides the most accurate and detailed information about the shortcut's target, which is essential for understanding what the shortcut would execute.

Exam trap

The trap here is assuming that jumplists or recent documents registry keys contain the same level of detail as the .lnk file itself, when they often only provide a reference to the file.

17
MCQmedium

An analyst discovers a file on a system that appears to be a 'hidden' executable. Which attribute of the NTFS file system, if modified, is a common indicator of a user attempting to conceal a file from standard Explorer views?

A.File Creation Timestamp
B.File Attribute Flags (MFT)
C.Extended Attributes (EA)
D.Access Control List (ACL)
AnswerB

The MFT stores the attributes for every file on an NTFS volume. The 'Hidden' attribute flag, when set, instructs the operating system to omit the file from standard folder views. Identifying this flag is essential for uncovering files that the attacker intentionally obscured from the user.

Why this answer

NTFS file attributes allow users to hide files from the standard Windows Explorer interface. By checking the File Attributes field in the Master File Table (MFT), an analyst can identify files marked with the 'Hidden' or 'System' attribute. This is a common, albeit simple, anti-forensics technique used by adversaries to prevent casual discovery of malicious binaries or staged data, and it is the first step in identifying deliberate concealment attempts.

Exam trap

Candidates often try to find the hidden file by searching for specific Registry keys, forgetting that the 'Hidden' attribute is a file-level metadata property stored within the MFT.

18
MCQhard

An investigator is analyzing the Windows Event Logs and finds Event ID 4697. What is the primary significance of this event in the context of forensic analysis?

A.It records the deletion of a user account from the local database.
B.It logs that a system service was started by the Service Control Manager.
C.It signals the installation of a new service on the system.
D.It documents a failed attempt to modify an existing service.
AnswerC

Event 4697 tracks service installation. Attackers often install services to maintain persistence, ensuring their malware runs with high privileges after a reboot. Detecting this event allows the investigator to extract the service path and identify the malicious binary that was dropped and registered for automatic execution.

Why this answer

Event ID 4697 indicates that a new service was installed on the system. This is a common technique for attackers to establish persistence. By monitoring this event, analysts can identify when malicious binaries were registered as services to run automatically upon system boot.

This is critical for uncovering hidden persistence mechanisms and identifying the service name, binary path, and account used to execute the potentially malicious code.

Exam trap

Candidates frequently confuse Event ID 4697 with general service start events, failing to realize it specifically logs the installation of a new service, a common persistence indicator.

19
MCQmedium

What is the primary function of the ShellBags artifact in a Windows forensic investigation?

A.To track the history of web browser searches.
B.To log file deletion events in the Recycle Bin.
C.To demonstrate that a user navigated to a specific folder.
D.To record the last time a system was rebooted.
AnswerC

ShellBags registry keys are updated when a user opens a folder. Because these keys persist even after folders are deleted, they are excellent evidence for showing the user was present in a directory. This helps confirm user knowledge of specific files or directories during a forensic examination.

Why this answer

ShellBags are registry entries that store folder view preferences, such as window size, icon position, and folder sorting. For forensics, they are incredibly useful for proving that a user navigated to a specific directory in Windows Explorer. This is critical for demonstrating user intent, as it shows which folders were browsed, even if those folders were later deleted or were located on removable media that is no longer connected.

Exam trap

Candidates often assume ShellBags only track files that currently exist, failing to realize the artifact persists even after the target folders or external drives have been removed.

20
Multi-Selecthard

An analyst is examining a Windows 10 system to determine if a specific user account was used to access files on a remote share. Which two artifacts would provide the most direct evidence of this activity? (Choose two.)

Select 2 answers
A.Security Event ID 4624 with Logon Type 3
B.UserAssist registry keys
C.Prefetch files for the remote access client
D.Security Event ID 5140 for a network share object
E.Sysmon Event ID 3 (Network Connection)
AnswersA, D

Security Event ID 4624 with Logon Type 3 indicates a network logon, which occurs when a user accesses a remote share. It records the account name, logon time, and source network address. This directly evidences remote file share access, making it a primary artifact for the scenario.

Why this answer

Security Event ID 4624 with Logon Type 3 and Event ID 5140 both directly record network logons and share access, respectively. They provide the account, timestamp, and share details needed to prove a user accessed a remote share. The other artifacts lack the specificity to directly evidence this activity.

Exam trap

The trap here is assuming that network connection logs or execution artifacts can prove file share access, when only specific security events like 4624 Type 3 and 5140 capture the account and share details.

21
MCQmedium

Which of the following describes the correct function of the $MFT (Master File Table) in an NTFS-formatted Windows volume?

A.It is an application log that tracks system crashes.
B.It holds the metadata for all files on the volume.
C.It stores user credentials for encrypted files.
D.It is only used to store files larger than 1GB.
AnswerB

The MFT acts as the central index of the NTFS file system. It contains critical metadata like timestamps and data pointers for every file. This is the foundation of digital forensic file analysis, enabling investigators to recover evidence of files, even after they have been deleted by users.

Why this answer

The MFT is the central database of an NTFS volume. It stores metadata for every file and directory on the disk, including file names, sizes, timestamps, and data runs. For forensic analysts, the MFT is the most important artifact, as it provides a comprehensive map of all files, including deleted ones, allowing for the reconstruction of the file system and identification of malicious files that were intentionally erased by an adversary.

Exam trap

Candidates often describe the MFT as the file data itself, rather than a metadata index, failing to distinguish between the file's contents and the record that describes the file.

22
MCQhard

An analyst is examining a Windows 10 system and finds that the ShimCache (AppCompatCache) contains an entry for a malicious executable. The analyst wants to determine whether the executable was actually executed on the system. Which additional artifact should the analyst examine to confirm execution?

A.SRUM (System Resource Usage Monitor)
B.Amcache.hve
C.Prefetch files
D.UserAssist
AnswerC

Prefetch files are created when an executable is run, and they record execution time and run count. If a Prefetch file exists for the malicious executable, it confirms that the program was executed on the system. ShimCache only indicates that the file was present and may have been executed, so Prefetch provides the necessary confirmation.

Why this answer

Prefetch files are created by the Windows Cache Manager when an executable is run, recording the execution time and run count. This directly confirms execution. ShimCache only shows that a file was present and may have been executed, so Prefetch is the best additional artifact to verify execution.

Amcache, UserAssist, and SRUM may provide supporting evidence but are not as definitive or comprehensive for this purpose.

Exam trap

The trap here is assuming that Amcache or ShimCache alone can prove execution, but they only show file presence or metadata; Prefetch is the artifact that definitively confirms execution.

23
MCQmedium

When reviewing Jump Lists on a Windows system, which file extension is commonly associated with the 'AutomaticDestinations' folder?

A..pf
B..automaticDestinations-ms
C..log
D..lnk
AnswerB

The .automaticDestinations-ms extension is used for the files stored in the AutomaticDestinations folder. These files contain lists of recently accessed items for a specific application. Identifying these files allows an analyst to extract document names, folder paths, and timestamps related to the user's recent file interaction history.

Why this answer

Jump Lists, located in the AutomaticDestinations and CustomDestinations folders, track recently accessed files and applications. The files are identified by an AppID, which is a hash of the application's path. These files often end with the .automaticDestinations-ms extension.

They are vital for identifying files opened by users, providing insight into document access, media playback, and tool usage that may relate to intellectual property theft or evidence of work.

Exam trap

Candidates often assume all Jump List files share the same extension, failing to differentiate between the 'AutomaticDestinations' and 'CustomDestinations' naming conventions used by the operating system.

24
MCQeasy

An investigator is examining a Windows 10 system and finds a prefetch file named 'POWERSHELL.EXE-12345678.pf' in the C:\Windows\Prefetch folder. What is the primary forensic value of this artifact?

A.It contains the full command-line arguments used when PowerShell was launched.
B.It indicates that PowerShell was installed as a service on the system.
C.It confirms that PowerShell was executed and provides the last execution time and number of times run.
D.It provides a list of all files accessed by PowerShell during its execution.
AnswerC

Prefetch files are created when an executable is run, and they record the last execution time and run count. The presence of a prefetch file for POWERSHELL.EXE indicates that PowerShell was executed on the system. The timestamp embedded in the .pf file can be parsed to determine the last execution time, which is valuable for timeline analysis.

Why this answer

The correct answer is that the prefetch file confirms execution and provides last execution time and run count. Prefetch files are created by the Windows Prefetcher to optimize application startup, and they include metadata such as the last run time and number of executions. This makes them a key artifact for determining if an executable like PowerShell was run, and when.

Exam trap

The trap here is assuming prefetch files store command-line arguments or complete file access lists, when they only provide execution metadata.

25
MCQmedium

An analyst is examining a Windows 10 host and finds that a suspicious process was launched shortly after a user logged on. To determine the exact time the process was created and capture its parent-child relationship, which artifact should the analyst prioritize?

A.Prefetch files in C:\Windows\Prefetch
B.UserAssist registry keys
C.Amcache.hve registry hive
D.Sysmon Event ID 1 (Process Creation) in the Windows Event Log
AnswerD

Sysmon Event ID 1 logs detailed process creation events, including the exact UTC timestamp, process GUID, image path, command line, and parent process ID. This directly answers when the process started and its parent-child relationship. If Sysmon was installed and configured, this is the most precise and reliable artifact for the scenario.

Why this answer

Sysmon Event ID 1 provides the most granular and reliable data for process creation, including exact timestamps and parent-child relationships. Other artifacts like Prefetch, Amcache, and UserAssist offer execution evidence but lack the precision and relationship details needed to reconstruct the sequence of events accurately.

Exam trap

The trap here is assuming that any execution artifact, such as Prefetch or Amcache, provides process creation timestamps and parent-child links, when only Sysmon Event ID 1 does so with the needed fidelity.

26
MCQmedium

An analyst is reviewing a Windows 10 endpoint and finds that a scheduled task was created to run a PowerShell script at logon. The task was likely created by an attacker to maintain persistence. Which artifact should the analyst examine to determine the exact time the task was registered and the user account that created it?

A.The Security event log, filtering for event ID 4698
B.The Task Scheduler operational event log (Microsoft-Windows-TaskScheduler/Operational.evtx)
C.The registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache
D.The Task Scheduler operational log, filtering for event ID 106
AnswerA

Event ID 4698 is generated when a scheduled task is created. It includes the task name, the user account that created it, and a timestamp. This directly answers the question of when the task was registered and who registered it, making it the most reliable artifact for this scenario.

Why this answer

Security event ID 4698 is the definitive artifact for scheduled task creation because it captures the task name, the creating user, and the timestamp. Other artifacts like the Task Scheduler operational log or registry keys may show the task exists or when it ran, but they do not reliably provide both the creator identity and the exact creation time, which are critical for attribution in an intrusion investigation.

Exam trap

The trap here is assuming the Task Scheduler operational log (event ID 106) provides user attribution for task creation, when it only records that a task was registered without identifying the account responsible.

27
MCQmedium

When analyzing the Windows Registry, what is the primary purpose of the 'SAM' hive?

A.It stores the system's network configuration and IP addresses.
B.It tracks all executed application history.
C.It contains local user account data and password hashes.
D.It holds the logs for all system boot events.
AnswerC

The SAM hive is the repository for local user accounts. It stores account names, group membership, and password hashes. For forensic examiners, this is the primary source for identifying users on the system and potentially cracking passwords to determine the level of access an attacker gained.

Why this answer

The SAM (Security Accounts Manager) hive contains local user account information, including password hashes and group memberships. It is a critical target during forensic analysis for identifying user accounts, password history, and potential privilege escalation attempts. By extracting these hashes, analysts can perform offline cracking to reveal passwords, which is often necessary to understand the full extent of a compromised account's capability within the organization's network.

Exam trap

Candidates often confuse the SAM hive with the SYSTEM hive or security logs, failing to identify the SAM as the specific location for local user authentication data.

28
MCQmedium

During an intrusion investigation, an analyst needs to determine the exact moment a malicious service was installed on a Windows 10 host. The attacker deleted the service's executable and cleared the System event log. Which artifact should the analyst examine to recover the service installation timestamp?

A.SRUM (System Resource Usage Monitor) database
B.Registry key LastWrite time under HKLM\SYSTEM\CurrentControlSet\Services\<ServiceName>
C.Amcache.hve inventory entry for the service executable
D.Prefetch file for the service executable (e.g., SERVICENAME.EXE-XXXXXXXX.pf)
AnswerB

The Services registry key stores configuration for each installed service. When a service is created or modified, the LastWrite time of its subkey under CurrentControlSet\Services is updated. This timestamp persists even if the executable is deleted and event logs are cleared, providing a reliable forensic indicator of when the service was installed or last altered. Analysts can correlate this with other artifacts to confirm the installation time.

Why this answer

The Services registry key maintains configuration data for each service, and its LastWrite time updates upon creation or modification. This artifact survives executable deletion and log clearing, offering a reliable timestamp for service installation. Other artifacts like SRUM, Prefetch, or Amcache provide execution or resource usage context but not the specific service registration time.

Exam trap

The trap here is assuming that execution artifacts like Prefetch or Amcache can pinpoint service installation, when they actually indicate execution or file inventory.

Ready to test yourself?

Try a timed practice session using only Windows Artifact Analysis questions.