
GIAC Battlefield Forensics and Acquisition
Domain 3Objective 4
Acquiring RAM and OS Artifacts GBFA Practice Questions (Page 9)
Part of the Acquisition Techniques domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
6concepts
Questions 41–45
- 41
You need to acquire the Windows registry hives from a live system without altering the evidence. Which tool and method is most appropriate?
Select an answer first - 42
During a RAM acquisition, the responder calculates a SHA-256 hash of the memory image on the acquisition machine. Why is this hash important for the investigation?
Select an answer first - 43
A forensic responder needs to acquire memory from a system that is running a critical application. The responder has a software tool that requires the system to be rebooted into a special mode. The incident handler wants to minimize downtime. Which approach is MOST appropriate?
Select an answer first - 44
During a forensic response, you must collect evidence from a running Windows system. Which sequence best follows the order of volatility?
Select an answer first - 45
What is the primary purpose of hashing an OS artifact immediately after acquisition?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GBFA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.