
GIAC Battlefield Forensics and Acquisition
Domain 2Objective 2
Windows Filesystems GBFA Practice Questions (Page 2)
Part of the Filesystems and Data Storage domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
3concepts
Questions 6–10
- 6
In NTFS forensics, which artifact allows a file to have multiple data streams, and is often used to hide data from casual directory listings?
Select an answer first - 7
A forensic examiner is analyzing an NTFS volume and finds a file with a non-resident $DATA attribute. The file's run list indicates that the data is stored in clusters 100-105 and 200-205. What does this indicate?
Select an answer first - 8
A forensic examiner is analyzing an NTFS volume and finds a file with a $DATA attribute that is marked as sparse. What does this indicate about the file?
Select an answer first - 9
A forensic examiner is analyzing the MFT from a Windows 10 system. The examiner locates a file record with the FILE attribute present, but the $DATA attribute is marked as non-resident and the runlist is empty. What is the most likely condition of the file?
Select an answer first - 10
A forensic examiner is investigating a Windows 10 system that has both an NTFS system drive and an external USB drive formatted with exFAT. The examiner needs to recover a deleted file from the USB drive and also analyze the system drive for evidence of file access. Which combination of techniques is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.