
GIAC Battlefield Forensics and Acquisition
Domain 3Objective 4
Acquiring RAM and OS Artifacts GBFA Practice Questions (Page 2)
Part of the Acquisition Techniques domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
6concepts
Questions 6–10
- 6
What is the main purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 7
A forensic analyst is using the 'dd' command to acquire memory from a Linux system. The analyst notices that the output file is significantly smaller than the total RAM size. What is the MOST LIKELY reason for this discrepancy?
Select an answer first - 8
A forensic examiner needs to collect the contents of the Windows Event Logs from a live system to investigate a security incident. The system is running and the examiner wants to preserve the integrity of the logs. Which tool or method is MOST appropriate for this task?
Select an answer first - 9
An examiner needs to determine which programs were executed on a Windows system. Which OS artifacts should be examined?
Select an answer first - 10
A forensic examiner is collecting OS artifacts from a macOS system. The examiner needs to determine which applications were run by the user and when. The system is running and the examiner has administrative access. Which combination of artifacts would provide the MOST reliable evidence of application execution?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.