
GIAC Certified Forensic Analyst
Domain 2Objective 1
Introduction to Memory Forensics GCFA Practice Questions (Page 4)
Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 16–20
- 16
A memory analyst is examining a memory image from a compromised server. Which of the following are primary goals of memory analysis? Select all that apply.
Select an answer first - 17
A forensic examiner is explaining to a client why memory forensics is necessary even though a full disk image was already taken. Which statement best describes the unique value of memory forensics?
Select an answer first - 18
A forensic examiner is preparing to collect evidence from a live Windows server. The examiner wants to ensure that the most volatile data is collected first. Which of the following lists the data sources in the correct order from most volatile to least volatile?
Select an answer first - 19
A forensic analyst is called to a site where a server is suspected of being compromised. The server is running critical production services and cannot be shut down. The analyst must acquire memory while minimizing disruption. Which approach best balances forensic soundness and operational continuity?
Select an answer first - 20
Which type of data is typically found in a memory image but NOT in a traditional disk image?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.