Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Battlefield Forensics and Acquisition

Domain 6Objective 3

Using Forensic Tools for Triage GBFA Practice Questions (Page 5)

Part of the Triage and Manual Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
4concepts

Questions 21–25

  1. 21application · medium

    A corporate incident response team needs to triage a fleet of 50 Windows workstations after a suspected ransomware outbreak. The team has a central management server and wants to collect volatile data from all machines quickly. Which tool selection is most appropriate?

    Select an answer first
  2. 22foundation · easy

    An investigator collects volatile data from a suspect system and stores the output on a USB drive. Which of the following actions is essential to maintain the chain of custody?

    Select an answer first
  3. 23application · medium

    An investigator is triaging a Windows system that is part of a ransomware investigation. The system is running, and the investigator has a triage tool that can collect the registry, event logs, and recently accessed files. The tool also has a built-in write-blocker for the USB output. What is the most appropriate way to operate the tool?

    Select an answer first
  4. 24expert · hard

    An incident responder is triaging a Windows server that is both a domain controller and a file server. The server is running, but the attacker may have remote access. The responder has a triage tool that can collect the registry, event logs, and active network connections. The responder must balance the need to collect volatile data with the risk of alerting the attacker. What is the best approach?

    Select an answer first
  5. 25foundation · easy

    An investigator uses the command `memdump -p 1234` on a Windows system during triage. What is the primary purpose of this command?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.