
GIAC Certified Forensic Examiner
Domain 5Objective 1
File and Program Analysis GCFE Practice Questions (Page 2)
Part of the File and Program Analysis domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
10concepts
Questions 6–10
- 6
Which of the following is a volatile memory artifact that can be analyzed to identify running processes and loaded modules?
Select an answer first - 7
During a live forensic investigation, you need to capture the contents of the system's volatile memory. Which of the following is the most appropriate method?
Select an answer first - 8
During a malware investigation, you find a Windows service that is configured to start automatically. The service's binary path points to a file in the user's AppData directory. Which additional artifact would BEST confirm that this service is being used for persistence?
Select an answer first - 9
An analyst is examining a Windows 10 system and finds an unknown application installed in C:\Users\Public\AppData\Local\Temp. The application's executable has a valid digital signature from a reputable vendor, but the file name is 'svch0st.exe'. The analyst wants to determine if this is a legitimate application or malware. Which finding would most strongly suggest the application is malicious?
Select an answer first - 10
A Windows server was compromised, and the attacker used a PowerShell script to download and execute a payload. The examiner needs to determine the exact command line used by the attacker. Which log source would most likely contain this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.