Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 3Objective 1

Introduction to File System Timeline Forensics GCFA Practice Questions (Page 3)

Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
4concepts

Questions 11–15

  1. 11expert · hard

    A senior forensic analyst is leading an investigation of a data breach at a financial institution. The analyst has a forensic image of a Windows server and needs to build a timeline that covers a period of six months. The analyst must balance the need for comprehensive data with the time available for analysis. Which approach best balances completeness and efficiency?

    Select an answer first
  2. 12application · medium

    An analyst is investigating a case where an employee is suspected of stealing proprietary data. The timeline shows that a file named 'customers.xlsx' was accessed at 3:00 PM, and a USB device was connected at 3:05 PM. The analyst also finds that the employee's email account sent an attachment at 3:10 PM. Which conclusion is best supported by this evidence?

    Select an answer first
  3. 13expert · hard

    You are analyzing a timeline from a Windows system where a user is suspected of copying files to a USB drive. The timeline shows a large number of files were accessed in a short period. The USB drive was not imaged. Which additional evidence would most strongly support the hypothesis that files were copied to the USB drive?

    Select an answer first
  4. 14foundation · easy

    Which of the following best describes the value of timeline forensics over simply listing file metadata?

    Select an answer first
  5. 15application · medium

    A forensic analyst is investigating a suspected data exfiltration incident on a Windows 10 workstation. The analyst has a full disk image and needs to determine when a specific USB drive was first connected and which files were accessed from it. The analyst plans to build a timeline from file system metadata. Which approach will most effectively support this investigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.