
GIAC Battlefield Forensics and Acquisition
Domain 2Objective 2
Windows Filesystems GBFA Practice Questions (Page 5)
Part of the Filesystems and Data Storage domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
3concepts
Questions 21–25
- 21
A forensic examiner is analyzing an NTFS volume and needs to identify the size of a file's data. Which attribute in the MFT record should be examined?
Select an answer first - 22
A forensic examiner is analyzing a USB drive that was used to exfiltrate data from a Windows system. The drive is formatted with exFAT. Which of the following artifacts would the examiner expect to find on the drive?
Select an answer first - 23
A forensic examiner is analyzing an NTFS volume and needs to determine the original creation time of a file that has been renamed and moved multiple times. Which of the following are valid sources of timestamp information? (Select all that apply.)
Select an answer first - 24
An examiner is investigating a Windows system and needs to determine if a file was deleted from an NTFS volume. Which of the following artifacts would provide the most direct evidence of deletion?
Select an answer first - 25
A forensic examiner is comparing a FAT32 and an exFAT USB drive. Both contain deleted files. Which statement accurately describes a key difference in their recovery potential?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.