EC-CouncilEC-Council
312-49 · Question #545
312-49 Question #545: Real Exam Question with Answer & Explanation
Sign in or unlock 312-49 to reveal the answer and full explanation for question #545. The question stem and answer options stay visible for context.
Submitted by emma.c· Apr 18, 2026Computer Forensics Investigation Process
Question
Richard is extracting volatile data from a system and uses the command doskey/history. What is he trying to extract?
Options
- AEvents history
- BPreviously typed commands
- CHistory of the browser
- DPasswords used across the system
Unlock 312-49 to see the answer
You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Volatile data#Windows commands#Command history#Live forensics