
GIAC Certified Forensic Examiner
Domain 1Objective 1
Digital Forensic Fundamentals GCFE Practice Questions (Page 2)
Part of the Digital Forensic Fundamentals domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 6–10
- 6
A company wants to ensure that its incident response team can quickly and legally collect evidence from employee workstations. The legal department is concerned about employee privacy. Which policy should the company implement to support forensic readiness?
Select an answer first - 7
An examiner is called to a scene where a computer is running and the screen shows an open chat window. The examiner needs to preserve the evidence in a way that will be admissible in court. Which action should the examiner take FIRST?
Select an answer first - 8
An examiner is investigating a case of unauthorized data access. The examiner has identified a suspect file on a network share. What is the next step in the forensic process?
Select an answer first - 9
In the digital forensic process, which phase involves identifying potential sources of evidence and determining their relevance to the investigation?
Select an answer first - 10
What is the primary purpose of maintaining a chain of custody for digital evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.