Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 112-57 Exam - Topic 7 Question 14 Discussion

Harry, a security professional, was hired to identify the details of an attack that was initiated on a Windows system. In this process, Harry decided to check the logs of currently running applications and the information related to previously uninstalled or removed applications for suspicious events.Which of the following folders in a Windows system stores information on applications run on the system?
C) C:\Windows\Prefetch
A) C:\Windows\Book
B) C:\subdir
D) C:\Windows\debug

Eccouncil 112-57 Exam - Topic 7 Question 14 Discussion

Actual exam question for Eccouncil's 112-57 exam
Question #: 14
Topic #: 7
[All 112-57 Questions]

Harry, a security professional, was hired to identify the details of an attack that was initiated on a Windows system. In this process, Harry decided to check the logs of currently running applications and the information related to previously uninstalled or removed applications for suspicious events.

Which of the following folders in a Windows system stores information on applications run on the system?

Show Suggested Answer Hide Answer
Suggested Answer: C

On Windows systems, the Prefetch feature records execution-related artifacts to speed up subsequent program launches. When an executable is run, Windows often creates a .pf prefetch file in C:WindowsPrefetch that contains valuable forensic indicators such as the executable name (mapped into the prefetch filename), last run time(s) (depending on Windows version), run count (in many versions), and a list of files and directories referenced during startup. Because these artifacts can persist even after an application is later uninstalled or deleted, investigators commonly use the Prefetch directory to demonstrate that a program executed on a host and to help build timelines around suspicious activity. This is especially useful in intrusion investigations for identifying the execution of attacker tools, droppers, scripts launched via interpreters, or renamed binaries.

The other options are not standard repositories for program execution history. C:Windowsdebug may contain specific debug logs for certain components but is not the canonical execution-tracking folder. C:WindowsBook and C:subdir are not standard Windows forensic artifact locations. Therefore, the folder that stores information on applications run on the system is C:WindowsPrefetch (C).


Contribute your Thoughts:

0/2000 characters
Elouise
4 days ago
Prefetch is definitely the go-to for this kind of info!
upvoted 0 times
...
Shawn
9 days ago
I thought C:\subdir had some logs too?
upvoted 0 times
...
Natalie
14 days ago
Wait, is C:\Windows\debug not relevant?
upvoted 0 times
...
Hyman
19 days ago
Totally agree, that's the right folder!
upvoted 0 times
...
Kandis
24 days ago
C:\Windows\Prefetch stores info on applications.
upvoted 0 times
...
Amber
29 days ago
I thought the debug folder was for error logs, but I can't recall if it also tracks application usage. This is tricky!
upvoted 0 times
...
Rasheeda
1 month ago
I practiced a similar question where we had to identify where Windows logs application activity, and I feel like it was definitely related to Prefetch.
upvoted 0 times
...
Leanora
1 month ago
I'm not entirely sure, but I remember something about logs being stored in the debug folder. Could that be relevant here?
upvoted 0 times
...
Blossom
1 month ago
I think the Prefetch folder might be the right answer since it stores data about applications that have been run to speed up their launch times.
upvoted 0 times
...

Save Cancel