
GIAC Battlefield Forensics and Acquisition
Domain 2Objective 2
Windows Filesystems GBFA Practice Questions (Page 1)
Part of the Filesystems and Data Storage domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
3concepts
Questions 1–5
- 1
An examiner is investigating a Windows system and needs to determine if a file was downloaded from the internet. Which of the following artifacts would provide the most direct evidence?
Select an answer first - 2
A forensic examiner is analyzing a 4 GB USB drive formatted with FAT32. The drive contains a deleted 2 GB file. The examiner wants to recover the file. Which statement about FAT32 is most relevant to the recovery effort?
Select an answer first - 3
When a file is deleted in NTFS, what typically remains on disk that is of forensic interest?
Select an answer first - 4
A forensic examiner is analyzing a 1 GB USB drive formatted with FAT16. The examiner needs to determine the cluster size. Which of the following structures would provide this information?
Select an answer first - 5
Which data structure in FAT12/16/32 filesystems is used to track the allocation status of each cluster and the chain of clusters that make up a file?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.