
GIAC Battlefield Forensics and Acquisition
Domain 5Objective 2
Working with Evidence Files GBFA Practice Questions (Page 9)
Part of the Network and Evidence Handling domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 41–44
- 41
An examiner has a raw image of a USB drive and needs to find a specific deleted document. The file system metadata is intact. Which analysis technique is most efficient for locating the deleted document?
Select an answer first - 42
When transporting physical evidence containing digital files, which procedure is most appropriate?
Select an answer first - 43
A forensic examiner must acquire the contents of a USB drive that contains a mix of deleted files and unallocated space. The examiner wants a single evidence file that preserves the entire device, including deleted data, and supports later verification of integrity. Which acquisition approach best meets these requirements?
Select an answer first - 44
A forensic examiner is about to analyze an evidence file that was acquired six months ago. The examiner verifies the SHA-256 hash and it matches the original acquisition hash. However, the examiner notices that the file's last modified timestamp is recent. What is the most appropriate conclusion?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GBFA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.