
GIAC Certified Forensic Examiner
Domain 6Objective 3
Email Analysis GCFE Practice Questions (Page 2)
Part of the User and Cloud Artifacts domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 6–10
- 6
Which of the following is the primary method for collecting email data from Microsoft 365 in a forensic investigation?
Select an answer first - 7
You are investigating a case involving a user's Microsoft 365 mailbox. The user has deleted several emails, and they are no longer visible in the Deleted Items folder. You need to recover these emails for evidence. Which method should you use first?
Select an answer first - 8
You are investigating a Windows workstation that uses Microsoft Outlook 2016 with a POP3 account. The user has deleted several emails from the Inbox and emptied the Deleted Items folder. Where should you look first for remnants of these emails?
Select an answer first - 9
In a typical Microsoft Outlook desktop installation on Windows, where are the user's mailbox items (emails, calendar, contacts) stored locally?
Select an answer first - 10
Which type of artifact is most useful for corroborating that a user actually read an email, in addition to the email itself?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.