Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 3Objective 1

Introduction to File System Timeline Forensics GCFA Practice Questions (Page 9)

Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
4concepts

Questions 41–45

  1. 41expert · hard

    A forensic analyst is correlating a file system timeline with network logs. The timeline shows that a file named 'data.zip' was created at 2:00 PM, and the network logs show an outbound connection to a cloud storage service at 2:05 PM. The analyst also finds that the user's browser history shows a visit to the cloud storage website at 2:04 PM. What is the most reasonable conclusion?

    Select an answer first
  2. 42application · medium

    You are investigating a data exfiltration incident. Your timeline shows a large archive file was created on a workstation at 2:00 PM. The corporate firewall logs show an outbound FTP connection to an external IP at 2:05 PM. Which additional evidence would most strengthen the case that the archive was exfiltrated?

    Select an answer first
  3. 43application · medium

    An analyst is building a timeline from a forensic image of a Linux server that hosts a web application. The goal is to determine if an attacker modified any web pages. The analyst has already extracted the file system metadata. Which additional data source should be incorporated to provide the most context for the timeline?

    Select an answer first
  4. 44expert · hard

    You are building a timeline for a system that was imaged after a power failure. The file system is NTFS. You notice that some file modification times in the $MFT are inconsistent with the $LogFile records. What is the most likely explanation?

    Select an answer first
  5. 45application · medium

    In a timeline you built from a Windows system, you notice a cluster of file creation events in the user's Downloads folder at 2:00 AM, followed by execution of a newly created .exe file. The user claims they were asleep. Which analysis technique is most appropriate to determine whether the activity was automated?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCFA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.