Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 2Objective 1

Introduction to Memory Forensics GCFA Practice Questions (Page 7)

Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 31–35

  1. 31application · medium

    A forensic analyst is triaging a laptop that was found powered on but locked. The analyst needs to determine if the system was used to access a cloud storage account. Which type of data would be most useful and where would it be found?

    Select an answer first
  2. 32foundation · easy

    How can anti-forensics techniques complicate memory analysis?

    Select an answer first
  3. 33expert · hard

    A forensic examiner is investigating a system that is suspected of being compromised by a rootkit. The rootkit is known to hide processes and network connections from the operating system. The examiner has a memory image of the system. Which approach is most likely to reveal the hidden processes?

    Select an answer first
  4. 34foundation · easy

    Which of the following is a common challenge in memory forensics?

    Select an answer first
  5. 35foundation · easy

    What is the primary purpose of memory acquisition in a forensic investigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.