
GIAC Certified Forensic Examiner
Domain 4Objective 2
Event Log Analysis GCFE Practice Questions (Page 2)
Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
5concepts
Questions 6–10
- 6
Which approach is most effective for correlating events from multiple logs to identify a user's actions across a system?
Select an answer first - 7
An examiner is investigating a Windows 10 system where a user allegedly accessed a confidential file on a network share. The Security log shows a successful logon (4624) at 09:00, but no network share access events (5140) are present. The examiner suspects the user accessed the share from a different session. Which approach would best determine whether the user accessed the share?
Select an answer first - 8
A forensic examiner needs to review the event logs from a Windows 10 workstation that was used to access sensitive files. The examiner wants to identify when the system was last shut down and when the user logged on. Which two event logs should be examined first?
Select an answer first - 9
Which command-line tool is built into Windows and can be used to query event logs using XPath queries or structured XML?
Select an answer first - 10
In a Windows event log entry, which field uniquely identifies the type of event that occurred, allowing analysts to search for specific activities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.