Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Certified Forensic Analyst

GCFA

The GIAC Certified Forensic Analyst (GCFA) certification validates your ability to collect and analyze data from computer systems to conduct formal incident investigations. It is designed for incident responders, threat hunters, and forensic analysts who must detect and eradicate advanced threats, including APTs and anti-forensic techniques. Earning GCFA proves you can handle complex digital forensic cases and serve as a vital line of defense for your organization.

417 practice questions · Updated 2026-07-30

5Domains
10Objectives
68Concepts
417Questions

GCFA Curriculum

Every domain, objective, and concept the GCFA exam measures.

  1. Incident Response Lifecycle
  2. Enterprise IR Team Roles
  3. IR Policy and Procedure
  4. IR Communication and Escalation
  5. Evidence Handling in Enterprise IR
  6. Enterprise IR Tools and Technologies
  7. Legal and Regulatory Considerations
  8. Business Continuity and Disaster Recovery
  9. Enterprise IR Metrics and Reporting

Introduction to Memory Forensics

5 concepts · 43 questions
  1. Definition of Memory Forensics
  2. Volatile vs. Non-Volatile Data
  3. Memory Acquisition Overview
  4. Memory Analysis Goals
  5. Challenges in Memory Forensics
  1. Volatile Artifact Identification
  2. Process Analysis for Malware
  3. Network Connection Artifacts
  4. Registry Artifact Analysis
  5. Correlating Volatile Artifacts
  1. Event Log Fundamentals
  2. Event Log Acquisition
  3. Event Log Parsing from Memory
  4. Correlating Event Artifacts
  5. Analyzing Security Events
  6. Analyzing System and Application Events
  7. Timeline Construction
  8. Anti-Forensic Evasion Detection

  1. Timeline Forensics Fundamentals
  2. Timeline Creation Process
  3. Timeline Analysis Techniques
  4. Timeline Correlation and Interpretation

File System Timeline Artifact Analysis

5 concepts · 25 questions
  1. Timeline Creation
  2. Timestamp Sources
  3. Timeline Correlation
  4. Timeline Analysis Techniques
  5. Artifact Interpretation

NTFS Artifact Analysis

16 concepts · 58 questions
  1. NTFS File System Basics
  2. MFT and File Record Analysis
  3. NTFS Attribute Types
  4. Resident vs Non-Resident Data
  5. MFT Entry Number and Sequence Number
  6. NTFS Timestamps Analysis
  7. Alternate Data Streams (ADS)
  8. NTFS Compression and Encryption
  9. Deleted File Recovery in NTFS
  10. NTFS Journal ($LogFile) Analysis
  11. USN Journal Analysis
  12. NTFS $MFT and $Bitmap Analysis
  13. NTFS $Boot and $Volume Analysis
  14. NTFS $Extend and System Files
  15. Timeline Construction from NTFS
  16. NTFS Artifact Correlation

Windows Artifact Analysis

10 concepts · 40 questions
  1. Windows Artifact Fundamentals
  2. Registry Analysis
  3. Filesystem Artifacts
  4. Prefetch and Superfetch Analysis
  5. Event Log Analysis
  6. Shortcut (LNK) and Jump List Analysis
  7. Thumbnail and Cache Analysis
  8. Volume Shadow Copy Analysis
  9. Memory Artifact Correlation
  10. Timeline Construction

  1. Baseline System Activity
  2. Baseline User Activity
  3. Recognizing Anomalies
  1. Malicious System Activity Identification
  2. Malicious User Activity Identification
  3. Correlation of System and User Activity
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCFA, so none is invented.