Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Battlefield Forensics and Acquisition

Domain 1Objective 2

Computer Fundamentals GBFA Practice Questions (Page 8)

Part of the Foundations and Preparation domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 3–4 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts

Questions 36–38

  1. 36application · medium

    An examiner is analyzing a disk image and needs to recover a deleted file. The file system is NTFS. Which structure is most likely to contain information about the deleted file's location?

    Select an answer first
  2. 37expert · hard

    An examiner is analyzing a disk image from a system that used full-disk encryption. The examiner has the decryption key and needs to mount the filesystem. The image contains an LUKS-encrypted partition. Which tool is most appropriate to access the filesystem?

    Select an answer first
  3. 38application · medium

    A forensic examiner is preparing to analyze a system that was running a modern operating system. The examiner needs to understand how the OS interacts with hardware to locate evidence of user activity. Which OS function is most directly responsible for managing access to the CPU and memory?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GBFA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.