
GIAC Certified Forensic Analyst
Domain 3Objective 1
Introduction to File System Timeline Forensics GCFA Practice Questions (Page 1)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
4concepts
Questions 1–5
- 1
An analyst is correlating a file system timeline with Windows Event Logs. The timeline shows that a file was modified at 3:00 PM, and the event log shows a successful logon for the user 'jsmith' at 2:59 PM from a workstation in the same office. What additional evidence would most strongly support the conclusion that jsmith modified the file?
Select an answer first - 2
An analyst is investigating a Windows system where the user claims they did not access a particular confidential file. The timeline shows that the file's last access time was updated, but the user's login times do not overlap with that access time. The analyst also finds that an antivirus scan ran at the same time. What is the most likely explanation for the access time update?
Select an answer first - 3
You are analyzing a timeline from a Linux server that was compromised. The timeline shows a file in /var/www/html was created at 2:00 AM, and the web server access log shows a POST request to that file at 2:01 AM. The server's system clock is known to be 5 minutes fast. The web server log timestamps are in UTC. Which time should you use for correlating the file creation with the web request?
Select an answer first - 4
In a timeline from a Windows system, you see a file that was created, then modified, and then the file's last access time was updated repeatedly over several days. The file is a DLL in the System32 folder. Which hypothesis is most plausible?
Select an answer first - 5
An analyst is reviewing a timeline and sees that a file was created, then modified, and then deleted, all within a five-minute window. The analyst also sees that a user logged in at the start of the window and logged off at the end. What is the most likely interpretation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.