
GIAC Certified Forensic Examiner
Domain 6Objective 3
Email Analysis GCFE Practice Questions (Page 1)
Part of the User and Cloud Artifacts domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 1–5
- 1
Which file format is commonly used by Mozilla Thunderbird to store email messages in a single file per folder?
Select an answer first - 2
Which of the following is a common file signature or pattern that a forensic tool might search for when carving for Outlook email data?
Select an answer first - 3
An analyst is investigating a spear-phishing email that contains a malicious attachment. The email passed SPF and DKIM, and the attachment is a Word document with macros. The analyst needs to determine if the attachment is malicious without executing it. Which approach is the most appropriate?
Select an answer first - 4
An analyst is examining an email with an attachment named 'invoice.pdf'. The file extension is .pdf, but the file signature (magic bytes) indicates it is actually a ZIP archive. What should the analyst do to safely analyze this attachment?
Select an answer first - 5
Which email header field provides a globally unique identifier for a specific email message, often used to correlate replies and track a message across systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.