
GIAC Battlefield Forensics and Acquisition
Domain 2Objective 2
Windows Filesystems GBFA Practice Questions (Page 4)
Part of the Filesystems and Data Storage domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
3concepts
Questions 16–20
- 16
An examiner is investigating a Windows system and needs to identify all files that have been accessed recently. Which of the following would provide the most comprehensive list?
Select an answer first - 17
A forensic examiner is analyzing an NTFS volume and finds a file with an alternate data stream (ADS) named ':Zone.Identifier'. What is the most likely origin of this ADS?
Select an answer first - 18
In NTFS, which attribute is used to store the actual content of a small file directly within the file record?
Select an answer first - 19
A forensic examiner is analyzing a 2 GB USB drive formatted with FAT32. The examiner needs to recover a deleted file. Which of the following is the most important structure to examine?
Select an answer first - 20
An examiner is analyzing a USB drive formatted with exFAT. The examiner needs to determine if a file was deleted. Which of the following structures would provide the most direct evidence of deletion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.