Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 2Objective 1

Introduction to Memory Forensics GCFA Practice Questions (Page 6)

Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 26–30

  1. 26expert · hard

    An incident response team must acquire memory from a server that is part of a high-availability cluster. The server is currently failing over and the team has a narrow window before the system reboots. What is the most important consideration for the acquisition?

    Select an answer first
  2. 27expert · hard

    A forensic examiner is called to investigate a suspected data exfiltration on a Windows server. The server is running, but the examiner suspects the attacker may have installed a kernel-level rootkit that hides processes. The examiner must decide whether to acquire memory or rely on the system's built-in tools. Which consideration is most critical in this decision?

    Select an answer first
  3. 28expert · hard

    A forensic analyst is investigating a system that may have been compromised by a sophisticated attacker. The analyst suspects that the attacker used anti-forensic techniques to hide their activities. Which of the following is a common challenge in memory forensics that the analyst must consider?

    Select an answer first
  4. 29expert · hard · select all that apply

    A memory analysis of a compromised system reveals a suspicious process that is not visible in the standard process list but is detected by scanning for process objects in kernel memory. Which of the following techniques could the malware be using to hide? (Select all that apply.)

    Select an answer first
  5. 30expert · hard

    A memory dump from a compromised server shows no malicious processes, but the system is beaconing to an external IP. The analyst suspects the malware is running in kernel mode. Which approach would best confirm this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.