
GIAC Certified Forensic Analyst
Domain 4Objective 1
Windows Artifact Analysis GCFA Practice Questions (Page 4)
Part of the Windows Artifact Analysis domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
10concepts
Questions 16–20
- 16
Which browser artifact is most likely to contain a record of URLs visited, search terms, and cached web content?
Select an answer first - 17
What type of Windows artifact is a .lnk file, and what is its primary forensic value?
Select an answer first - 18
During a Windows forensic examination, an analyst wants to identify which applications were executed on the system. Which Windows artifact is specifically designed to record program execution times and is commonly used for this purpose?
Select an answer first - 19
What information is typically stored in a Windows Prefetch file that is valuable for forensic analysis?
Select an answer first - 20
An analyst is constructing a timeline for a malware infection. They have the following artifacts: Security event logs showing a logon at 10:00, Prefetch for the malware at 10:05, $MFT showing the malware file created at 10:04, and USN journal showing a file deletion at 10:06. Which sequence of events is most consistent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.