Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Battlefield Forensics and Acquisition

Domain 1Objective 2

Computer Fundamentals GBFA Practice Questions (Page 4)

Part of the Foundations and Preparation domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 3–4 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts

Questions 16–20

  1. 16application · easy

    A technician is troubleshooting a computer that fails to boot. The technician suspects the operating system is not loading correctly. Which component is most directly responsible for loading the operating system into memory during the boot process?

    Select an answer first
  2. 17application · medium

    A network forensic analyst is examining a packet capture and sees a destination IP address of 192.168.1.255. What does this address represent?

    Select an answer first
  3. 18foundation · easy

    Which file system is commonly used by modern Windows operating systems for system drives?

    Select an answer first
  4. 19expert · hard

    A forensic analyst is examining a network packet capture and sees a TCP packet with the flags PSH and ACK set. What is the most likely interpretation?

    Select an answer first
  5. 20expert · hard

    A forensic examiner is analyzing a disk image from a Linux system that used ext4. The examiner needs to recover a deleted file. Which of the following is the most significant challenge?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.