Courseiva

CCNA Windows Forensics Questions

11 questions · Windows Forensics · All types, answers revealed

1
MCQmedium

During a forensic examination, you find a Prefetch file named 'MALWARE.EXE-A1B2C3D4.pf'. What is the significance of the hexadecimal string appended to the filename?

A.It is a randomized identifier generated at system boot.
B.It represents the hash of the file's content.
C.It is a hash derived from the file's execution path.
D.It is the timestamp of the last execution.
AnswerC

The hash is calculated using the full path of the executable. This allows the system to store distinct prefetch information for applications sharing the same name but residing in different directories, providing forensic investigators with the exact location where the binary was executed from.

Why this answer

Windows Prefetch files store metadata about application execution to speed up startup times. The hash appended to the filename is calculated based on the path from which the application was executed. This allows investigators to differentiate between multiple instances of the same binary running from different directories, which is a common technique used by attackers to hide malicious binaries in non-standard, obfuscated system locations.

Exam trap

Candidates often mistakenly believe the hash represents the file content itself (like an MD5 or SHA256), missing that Prefetch hashes are specifically tied to the execution path.

2
MCQmedium

An incident responder needs to determine the last time a specific user interacted with a Windows workstation. Which registry hive should be analyzed to retrieve the LastWrite time of the user's NTUSER.DAT file?

A.SYSTEM hive
B.SAM hive
C.SOFTWARE hive
D.The user's NTUSER.DAT hive
AnswerD

The NTUSER.DAT hive is the root of the HKEY_CURRENT_USER registry branch. Examining the file system metadata for this specific file directly reveals the LastWrite time, indicating when the hive was last flushed to disk, which corresponds to the last time the user profile was active.

Why this answer

The NTUSER.DAT file contains user-specific registry settings. Analyzing the LastWrite time of this hive provides insight into when the user profile was last active. In forensics, tracking user activity is critical for establishing a timeline of unauthorized access or insider threats.

Examiners must cross-reference this with event logs to confirm if the activity aligns with the suspected malicious incident window.

Exam trap

Candidates often choose the SYSTEM registry hive or the SAM hive, forgetting that user-specific activity is stored within the user's own profile hive (NTUSER.DAT).

3
Multi-Selectmedium

An analyst is examining a Windows 10 host suspected of being used to stage and exfiltrate data. The analyst wants to identify evidence of files that were recently opened or created by the user, and of USB mass storage devices that were previously connected. Which two artifacts should the analyst examine to address these goals? (Choose two.)

Select 2 answers
A.The RecentApps key under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Search
B.The Amcache.hve Root\File key
C.The SYSTEM hive's USBSTOR key at ControlSet001\Enum\USBSTOR
D.The SRUM database's Network Data Usage table
E.The RecentDocs key under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
AnswersC, E

The USBSTOR key in the SYSTEM hive records USB mass storage devices that have been connected to the host, including device identifiers, serial numbers, and friendly names. It is the primary artifact for proving prior USB mass storage connections. It does not track individual file opens, so it addresses the USB portion of the investigation rather than the recent-file portion.

Why this answer

RecentDocs in NTUSER.DAT preserves recently opened documents with shell item paths, addressing the recent-file goal, while the SYSTEM hive's USBSTOR key enumerates USB mass storage devices that were previously connected. Together they cover both investigative objectives. The other artifacts either record application usage, executable metadata, or network statistics, none of which map to the stated goals.

Exam trap

The trap here is reaching for application-usage or network-usage artifacts that feel related to user activity but do not actually enumerate recently opened documents or previously connected USB mass storage devices.

4
MCQhard

An examiner is reviewing a Windows 11 workstation seized during an insider-threat investigation. The suspect denies ever connecting removable media, but the examiner finds a file named 'E01' inside 'C:\Windows\INF\' with no corresponding setupapi.dev.log entries for USB devices. Which artifact should the examiner correlate to confirm the specific USB storage device that was connected and its serial number?

A.The NTFS USN journal on the system volume
B.The USBSTOR registry key under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
C.The MountedDevices registry key under HKLM\SYSTEM\MountedDevices
D.The Windows Portable Devices (WPD) registry key under HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices
AnswerB

USBSTOR records every USB mass-storage device that has been connected, storing the device descriptor, vendor, product, and a unique serial number in the subkey name. Correlating the serial in USBSTOR with setupapi.dev.log entries confirms the specific device even when log entries appear missing, because USBSTOR persists after disconnection and can survive log rotation or selective deletion. This directly addresses the insider-threat scenario.

Why this answer

The USBSTOR registry key is the authoritative artifact for identifying USB mass-storage devices that have been attached to a Windows system. Each subkey contains a unique device instance ID that includes the vendor, product, and serial number, allowing an examiner to confirm the exact device even when setupapi.dev.log entries are absent or incomplete. Correlating USBSTOR with other artifacts provides a robust evidentiary link.

Exam trap

The trap here is assuming that the absence of setupapi.dev.log entries means no USB device was ever connected, ignoring the persistent USBSTOR registry key that records device serial numbers independently.

5
MCQhard

Refer to the exhibit. An investigator identifies this registry key. What is the primary purpose of this information in a forensic investigation?

A.It defines the system's default language settings.
B.It maps Security Identifiers (SIDs) to user profile directories.
C.It logs every application the user has executed.
D.It lists all installed software on the system.
AnswerB

ProfileList is the authoritative source for locating where a user's profile resides on the disk. For an investigator, this is essential to verify account existence and identify the correct directory path for further analysis of user-specific artifacts that might contain evidence of attacker activity.

Why this answer

The ProfileList key maps SIDs to user profile paths. This is critical because an attacker may create a temporary or hidden account. By identifying the exact path to the user profile, the investigator knows where to look for user-specific artifacts like NTUSER.DAT, browser history, and temporary files.

This mapping is the starting point for scoping user-level malicious activities and ensuring that no hidden accounts are overlooked during the investigation.

Exam trap

Candidates often confuse the ProfileList registry key with general system configuration keys. They fail to recognize that this specific key is the primary link between user SIDs and profile paths.

6
MCQmedium

An incident responder is analyzing a Windows 10 workstation that is suspected of being used to exfiltrate data. The responder runs 'wevtutil qe Security /q:"*[System[(EventID=5156)]]" /f:text' but finds no events. Which action will most reliably produce the network connection telemetry the responder needs for this investigation?

A.Set the Security log retention method to 'Overwrite events as needed' and increase the maximum log size to 1 GB.
B.Run 'netsh trace start capture=yes' and review the resulting ETL file in Event Viewer under the Microsoft-Windows-TCPIP operational log.
C.Enable the 'Audit Process Creation' policy and configure the 'Include command line in process creation events' setting to capture outbound connections.
D.Enable the 'Audit Filtering Platform Connection' policy under Advanced Audit Policy Configuration and ensure the Security log is large enough to retain events.
AnswerD

Event ID 5156 is logged only when the Filtering Platform Connection subcategory is audited. By default it is not enabled, so the query returns nothing. Enabling this subcategory via Advanced Audit Policy Configuration and provisioning sufficient Security log capacity allows the responder to capture allowed and blocked connection events with process, user, and port details needed to trace exfiltration.

Why this answer

Event ID 5156 is generated only when the Filtering Platform Connection audit subcategory is enabled through Advanced Audit Policy Configuration; the default configuration does not log these events, which explains the empty query result. Enabling the subcategory and providing adequate log capacity gives the responder the process, user, and endpoint details required to trace the suspected exfiltration activity on the workstation.

Exam trap

The trap here is assuming that the Security log records network connections by default, when the Filtering Platform Connection subcategory must be explicitly enabled.

7
MCQhard

An examiner is analyzing a Windows 10 endpoint and finds that the user account was deleted before acquisition, but the examiner still needs to determine which files that user recently opened from a network share. The user's profile folder was also removed. Which artifact is most likely to retain this information?

A.The Security event log's object access auditing entries in the Security.evtx file
B.The SRUM database's Application Resource Usage table
C.The NTUSER.DAT hive from the deleted user's profile folder
D.The UsrClass.dat hive from the deleted user's profile folder
AnswerA

If object access auditing was enabled, the Security event log records file access events, including the account name, the object path, and the share accessed. Because the log is stored in C:\Windows\System32\winevt\Logs and is system-scoped, it survives deletion of the user profile and account. It is the most likely remaining source for the user's recent file opens from a network share.

Why this answer

Object access auditing, when enabled, writes file access events to the Security event log, which is system-scoped and stored under winevt\Logs, so it survives deletion of the user account and profile. Per-user hives such as NTUSER.DAT and UsrClass.dat are removed with the profile, and SRUM records resource usage rather than file opens.

Exam trap

The trap here is assuming that user-scoped artifacts such as NTUSER.DAT and UsrClass.dat remain available after the profile is deleted, when in fact they are removed with the profile folder.

8
MCQhard

A forensic examiner is reviewing an NTFS volume from a Windows 11 laptop. The user claims a sensitive spreadsheet was only opened and never modified or renamed. The examiner notes that the $STANDARD_INFORMATION timestamps for the file are all recent, but the $FILE_NAME timestamps are from several months earlier. Which explanation best accounts for this discrepancy?

A.Windows 11 disables $FILE_NAME timestamp updates by default for user documents, so the older values simply reflect the file's creation date.
B.The file was accessed by a program that updated the $STANDARD_INFORMATION timestamps, and this behavior is a known anti-forensic technique or normal filesystem behavior depending on the API used.
C.The $FILE_NAME timestamps record when the file was last backed up, while the $STANDARD_INFORMATION timestamps record live activity, so they legitimately differ after any backup.
D.The file was copied onto the volume from a remote share, which rewrote the $STANDARD_INFORMATION times while preserving the $FILE_NAME times from the source.
AnswerB

NTFS stores two sets of timestamps: $STANDARD_INFORMATION, which many APIs update, and $FILE_NAME, which is typically updated only on rename or certain metadata changes. Tools and some APIs can modify $STANDARD_INFORMATION times without touching $FILE_NAME, producing exactly this discrepancy. It is a well-documented artifact and a common timestomping indicator, so this explanation fits the evidence best.

Why this answer

NTFS maintains parallel timestamps in $STANDARD_INFORMATION and $FILE_NAME. Many APIs and many anti-forensic tools update only the $STANDARD_INFORMATION set, leaving $FILE_NAME untouched. A recent $STANDARD_INFORMATION paired with an older $FILE_NAME is a classic timestomping indicator and directly explains the discrepancy the examiner observed.

Exam trap

The trap here is treating the two NTFS timestamp sets as always identical and therefore dismissing the discrepancy instead of recognizing it as a timestomping or API-behavior indicator.

9
MCQmedium

Refer to the exhibit. An investigator is auditing logon events. Which Event ID indicates a successful network logon (Type 3) to the machine?

A.Event ID 4625
B.Event ID 4624 with Logon Type 3
C.Event ID 4624 with Logon Type 2
D.Event ID 4672
AnswerB

Event ID 4624 is the standard success audit for logons. Logon Type 3 is explicitly defined by Microsoft as a network logon, which occurs when a user or computer connects to a shared resource or service on the target machine from a remote source location.

Why this answer

Event ID 4624 records successful logons, and the Logon Type field specifies the method used. A Type 3 logon represents a network connection, often associated with remote file access or service authentication. Identifying these events is essential for detecting lateral movement or unauthorized access via SMB, as attackers frequently use network logons to propagate through a compromised environment using stolen credentials.

Exam trap

Candidates often memorize Event ID 4624 but forget to check the specific Logon Type, confusing interactive console logons with remote network connections.

10
MCQmedium

An incident responder collects volatile data from a compromised Windows 10 workstation before pulling the power. The attacker used a custom executable that is no longer present on disk, but the responder needs to confirm which process spawned it and what child processes it created. Which artifact should the responder examine to establish this parent-child process relationship?

A.The SRUM database's Application Resource Usage table
B.The Sysmon Event ID 1 records in the Microsoft-Windows-Sysmon/Operational log
C.The $MFT entries for the volume where the executable ran
D.The Amcache.hve registry hive's Root\InventoryApplicationFile key
AnswerB

Sysmon Event ID 1 (Process Create) captures the image path, command line, hashes, parent process ID, and parent image for each new process. This directly documents which process spawned the attacker's executable and the children it created, even after the binary is deleted. It is the most reliable volatile artifact for reconstructing the parent-child relationship in this scenario.

Why this answer

Sysmon's Process Create event records the image, command line, hashes, and both parent process ID and parent image for every new process, which is exactly the data needed to reconstruct a process tree after the binary is gone. Other artifacts such as Amcache, $MFT, and SRUM may show that a file existed or ran but do not preserve runtime parent-child relationships.

Exam trap

The trap here is assuming that any artifact showing an executable ran (Amcache, SRUM, Prefetch) also preserves the parent-child process relationships, when only process-creation telemetry such as Sysmon Event ID 1 does.

11
MCQmedium

When investigating a Windows system, which file system feature is responsible for recording the file metadata including timestamps for created, modified, and accessed (MACE) times?

A.Registry hives
B.Master File Table (MFT)
C.Event Logs
D.Prefetch files
AnswerB

The MFT is a relational database that acts as the backbone of NTFS. It stores the metadata for every file and folder on the partition, including the primary timestamps (Standard Information and File Name attributes) used for forensic timeline analysis and detecting file modification or deletion events.

Why this answer

The Master File Table (MFT) is the core of the NTFS file system. Every file on an NTFS volume has at least one entry in the MFT. These entries contain the MACE times, which are critical for building a timeline of events.

If these times are altered, it often indicates anti-forensic activity, making the MFT the primary source for verifying file history and integrity during an investigation.

Exam trap

Candidates often confuse file system metadata structures with application logs or registry hives when identifying where MACE timestamps are natively recorded on NTFS volumes.

Ready to test yourself?

Try a timed practice session using only Windows Forensics questions.