
GIAC Certified Enterprise Defender
Domain 2Objective 2
Digital Forensics Concepts and Application GCED Practice Questions (Page 5)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
9concepts
Questions 21–25
- 21
What is steganography?
Select an answer first - 22
An incident responder needs to create a forensic image of a USB drive that may contain evidence. The responder has a write-blocker and forensic imaging software. Which step is essential to ensure the image is a valid bit-for-bit copy?
Select an answer first - 23
An examiner is analyzing a forensic image and finds that the suspect used full-disk encryption. The examiner has the suspect's password, but the encryption software also supports a recovery key. Which approach is MOST likely to successfully decrypt the drive while preserving the integrity of the evidence?
Select an answer first - 24
Which statement best defines digital forensics in the context of incident response?
Select an answer first - 25
A forensic examiner is collecting evidence from multiple computers at a crime scene. To ensure the evidence is admissible, which practice is MOST important during the collection phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.