Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Battlefield Forensics and Acquisition

Domain 6Objective 3

Using Forensic Tools for Triage GBFA Practice Questions (Page 4)

Part of the Triage and Manual Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
4concepts

Questions 16–20

  1. 16expert · hard

    A forensic examiner is documenting a triage that involved multiple tools and a chain of custody that passed through several hands. The examiner needs to ensure that the documentation is legally defensible. Which documentation practice is most important?

    Select an answer first
  2. 17foundation · easy

    During a triage of a suspect Windows workstation, an investigator needs to quickly capture running processes, network connections, and logged-on users without altering the system. Which tool is most appropriate for this task?

    Select an answer first
  3. 18application · medium

    A responder is triaging a Windows 10 machine suspected of malware infection. The machine is running and the responder has a trusted USB toolkit. The responder needs to collect volatile data without altering the system more than necessary. Which tool usage is most appropriate for this task?

    Select an answer first
  4. 19application · medium

    A small law enforcement agency has a limited budget and needs to perform triage on Windows and Linux systems in the field. The investigators are not deeply technical but need to collect memory, network connections, and running processes quickly. Which tool selection is most appropriate for this context?

    Select an answer first
  5. 20application · medium

    A small law enforcement agency is preparing for a potential cybercrime investigation. They have limited budget and need to triage a Windows system that may contain evidence of fraud. The system is running, and they have a forensic laptop with write-blocker and imaging software. Which triage tool selection is most appropriate for this context?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.