
GIAC Battlefield Forensics and Acquisition
Domain 6Objective 3
Using Forensic Tools for Triage GBFA Practice Questions (Page 7)
Part of the Triage and Manual Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
4concepts
Questions 31–35
- 31
A corporate incident response team needs to triage a macOS system that may be involved in intellectual property theft. The team has a limited budget and needs to collect volatile data and document the process. Which tool selection is most appropriate?
Select an answer first - 32
A field investigator arrives at a small office with a suspected data-exfiltration incident. The suspect's Windows 10 workstation is powered on and logged in, but the user is not present. The investigator has a write-blocker, a USB forensic toolkit, and a portable triage tool that can capture running processes, network connections, and recent files. The office has no network connectivity for the forensic laptop. What should the investigator do first?
Select an answer first - 33
An incident response team is preparing a triage kit for a corporate environment that includes both Windows 10 and Linux servers. The team has a limited budget and must choose tools that can be used by junior analysts. The team also needs to collect memory, network connections, and running processes, and must document the process for potential legal action. Which tool selection strategy best meets these competing requirements?
Select an answer first - 34
A forensic examiner is using a triage tool that automatically logs all actions and generates a report. The examiner also manually records notes about the scene. What is the most important reason to keep the manual notes?
Select an answer first - 35
A forensic examiner used a triage tool to collect data from a suspect machine. The examiner later needs to prove that the collected data has not been altered since acquisition. What is the most appropriate action to support this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.