
GIAC Certified Forensic Analyst
Domain 2Objective 1
Introduction to Memory Forensics GCFA Practice Questions (Page 3)
Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 11–15
- 11
An analyst is about to acquire memory from a system that is suspected of running anti-forensic tools. The analyst is concerned that the acquisition tool may be tampered with. Which approach best mitigates this risk?
Select an answer first - 12
A forensic examiner is analyzing a memory dump and wants to identify which files were opened by a specific process. Which memory artifact would be most useful?
Select an answer first - 13
A forensic analyst is analyzing a memory image and finds a process that has a network connection to an IP address that is flagged as malicious. The analyst wants to determine if the process is malware. Which additional memory analysis step would be most helpful?
Select an answer first - 14
A junior analyst is learning about memory forensics and asks why it is important to acquire memory before shutting down a system. Which response best explains the role of memory forensics in digital investigations?
Select an answer first - 15
A memory analysis reveals an unknown process that is injecting code into a legitimate system process. What is the primary goal of this technique from the malware's perspective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.