
GIAC Battlefield Forensics and Acquisition
Domain 3Objective 1
Dead Box Acquisition GBFA Practice Questions (Page 7)
Part of the Acquisition Techniques domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 31–35
- 31
An examiner is acquiring a laptop with a 512 GB NVMe SSD. The examiner connects the SSD to a hardware write blocker and images it to a forensic image file. After imaging, the examiner verifies the hash. What does the hash verification actually prove?
Select an answer first - 32
An examiner is acquiring a drive that appears to have a hidden partition. The drive is recognized by the forensic tool, but the partition table shows only a small portion of the drive. The examiner suspects the drive has been manipulated to hide data. What is the most effective technique to recover the hidden data?
Select an answer first - 33
An examiner needs to acquire a drive that is larger than the available storage on the forensic workstation. The examiner must preserve the evidence but has limited time and storage. Which approach is most appropriate?
Select an answer first - 34
During dead box acquisition, why is it necessary to use a write blocker?
Select an answer first - 35
What does a bit-for-bit forensic image capture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.