
GIAC Certified Forensic Examiner
Domain 3Objective 1
Browser Structure and Analysis GCFE Practice Questions (Page 4)
Part of the Browser Forensics domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
12concepts
Questions 16–20
- 16
Which of the following is an example of a browser-generated forensic artifact that records the exact time a user visited a specific URL?
Select an answer first - 17
What is the primary purpose of correlating browser artifacts with system timelines in a forensic investigation?
Select an answer first - 18
In an investigation, you need to locate saved form data (e.g., names, addresses) from a suspect's Edge browser. Where should you look?
Select an answer first - 19
A user is suspected of using a browser's 'private mode' to visit a prohibited site. The browser history and cache show no trace of the visit. Which additional source of evidence might still reveal the activity?
Select an answer first - 20
A forensic analyst is examining a Windows system and wants to identify browser telemetry data that might reveal user activity even when history and cache are cleared. Which of the following is a browser-generated telemetry artifact that could provide such evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.