
GIAC Certified Forensic Examiner
Domain 6Objective 2
Cloud Storage Analysis GCFE Practice Questions (Page 8)
Part of the User and Cloud Artifacts domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
Questions 36–37
- 36
A forensic examiner is reconstructing the timeline of a data breach involving a cloud storage service. The examiner has the following artifacts: (1) sync logs from the user's laptop showing a file upload at 10:15, (2) cloud metadata showing the file was created at 10:20, (3) an email notification sent to the user at 10:25 confirming the upload, and (4) a firewall log showing an outbound connection to the cloud provider at 10:12. The user claims they were in a meeting from 10:00 to 11:00 and did not upload the file. Which artifact is MOST likely to be the most reliable indicator of when the upload actually occurred?
Select an answer first - 37
An examiner is analyzing a Windows 10 machine that had the Google Drive for Desktop client installed. The examiner finds a file in the DriveFS cache that is not present in the user's Google Drive account. What does this indicate?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.