
GIAC Battlefield Forensics and Acquisition
Domain 2Objective 1
Filesystem Fundamentals GBFA Practice Questions (Page 4)
Part of the Filesystems and Data Storage domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 16–20
- 16
A forensic examiner is analyzing a disk image from a Windows 10 system that uses BitLocker. The examiner needs to determine the partition layout and identify the BitLocker-encrypted partition. Which tool or method is most appropriate?
Select an answer first - 17
Which filesystem structure is most directly used by forensic tools to locate the starting cluster of a deleted file in a FAT filesystem?
Select an answer first - 18
A forensic examiner is analyzing a disk image from a Linux server that uses LVM. The examiner needs to acquire the logical volume that contains the `/home` directory. Which approach correctly identifies the logical volume?
Select an answer first - 19
Which filesystem type is the default for modern macOS system volumes and is characterized by copy-on-write metadata and strong encryption support?
Select an answer first - 20
A forensic examiner is trying to recover a deleted file from an ext4 filesystem. The file was deleted recently, and the filesystem has not been heavily used since. Which approach is most likely to recover the file's content?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.