Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Examiner

Domain 4Objective 2

Event Log Analysis GCFE Practice Questions (Page 7)

Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
5concepts

Questions 31–33

  1. 31foundation · easy

    An analyst sees Event ID 4624 in the Security log. What user action does this event typically indicate?

    Select an answer first
  2. 32expert · hard

    An analyst is investigating a user who allegedly accessed a confidential file. The analyst has enabled Object Access auditing and finds Event ID 4663 (file access) in the Security log. The event shows the file name and the user, but the analyst needs to determine if the user actually read the file or just opened it to view properties. Which field in the event entry should the analyst examine?

    Select an answer first
  3. 33application · medium

    An examiner is using Event Viewer to analyze a Windows 10 system. The examiner needs to find all events from the last 7 days that have a level of 'Error' or 'Critical' across multiple logs. What is the most efficient built-in method?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCFE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.