
GIAC Certified Forensic Examiner
Domain 6Objective 2
Cloud Storage Analysis GCFE Practice Questions (Page 3)
Part of the User and Cloud Artifacts domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
Questions 11–15
- 11
In a cloud storage client's synchronization log, what does an entry showing a 'download' action for a file typically indicate?
Select an answer first - 12
During a forensic examination of a Windows workstation, an investigator locates a folder containing files with names like '1234567890.cfg' and '1234567890.db'. These files are associated with a cloud storage client. What type of cloud storage artifact are these files most likely to represent?
Select an answer first - 13
A forensic examiner finds a cloud storage client's database file on a suspect's computer. The database contains tables with file paths, timestamps, and account information. Which table would MOST directly link a file to a specific user account?
Select an answer first - 14
Which artifact is most useful for correlating cloud storage activity to a specific user account?
Select an answer first - 15
A forensic examiner is investigating a case involving the Google Drive for Desktop client on a Windows machine. Which artifact would be most useful for identifying the Google account that was used to configure the client?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.