
GIAC Certified Forensic Examiner
Domain 5Objective 1
File and Program Analysis GCFE Practice Questions (Page 1)
Part of the File and Program Analysis domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
10concepts
Questions 1–5
- 1
You are investigating a case involving email communications. Which file format is commonly used by Microsoft Outlook to store email messages and can be found on the local system?
Select an answer first - 2
You are investigating a system and need to find evidence that a user opened a specific document from a USB drive. Which Windows artifact is most likely to contain this information?
Select an answer first - 3
A forensic examiner is investigating a case involving suspicious communications. The suspect used a desktop email client (e.g., Outlook) and also a messaging app. Which artifact would be most useful to correlate the timing of a specific email with a chat message?
Select an answer first - 4
A malware analyst suspects that a malicious program is set to run automatically every time the system starts, even before any user logs in. Which persistence mechanism would allow this?
Select an answer first - 5
An examiner is investigating a user's web activity on a Windows 10 system. The user is suspected of using a private browsing mode to access illegal content. The examiner finds that the user's browser history is empty, but the system's pagefile.sys contains fragments of web pages. Which conclusion is most defensible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.