
GIAC Certified Forensic Analyst
Domain 3Objective 1
Introduction to File System Timeline Forensics GCFA Practice Questions (Page 4)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
4concepts
Questions 16–20
- 16
An analyst is creating a timeline from a Linux system image to investigate unauthorized access. The system uses the ext4 file system. The analyst wants to include file metadata, directory entries, and journal data in the timeline. Which set of tools and data sources should be used?
Select an answer first - 17
Your timeline shows that a confidential PDF was modified at 3:15 PM. The user's email client shows an outbound message with that PDF attached at 3:20 PM. The user claims they never opened the file. Which interpretation is most defensible?
Select an answer first - 18
You are building a timeline for a Windows system that uses BitLocker. The system was imaged while powered off, and you have the recovery key. You need to include file system metadata from the encrypted volume. Which approach is correct?
Select an answer first - 19
During an investigation, you build a timeline that shows a user's document was created at 10:00 AM, but the user's alibi places them in a meeting from 9:00 to 11:00 AM. You also find that the user's workstation was remotely accessed via RDP at 9:45 AM. Which interpretation is most consistent with the evidence?
Select an answer first - 20
A forensic analyst is building a timeline for a case involving a Linux server. The analyst wants to include file system metadata from the ext4 journal, inodes, and directory entries. Which of the following best describes the primary purpose of including the journal in the timeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.