nerdexam
EC-CouncilEC-Council

312-49 · Question #545

312-49 Question #545: Real Exam Question with Answer & Explanation

Sign in or unlock 312-49 to reveal the answer and full explanation for question #545. The question stem and answer options stay visible for context.

Submitted by emma.c· Apr 18, 2026Computer Forensics Investigation Process

Question

Richard is extracting volatile data from a system and uses the command doskey/history. What is he trying to extract?

Options

  • AEvents history
  • BPreviously typed commands
  • CHistory of the browser
  • DPasswords used across the system

Unlock 312-49 to see the answer

You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Volatile data#Windows commands#Command history#Live forensics
Full 312-49 PracticeBrowse All 312-49 Questions