Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Examiner

Domain 5Objective 1

File and Program Analysis GCFE Practice Questions (Page 4)

Part of the File and Program Analysis domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
10concepts

Questions 16–20

  1. 16foundation · easy

    Which browser artifact is used to maintain session state and track user preferences, and can reveal information about a user's online activity?

    Select an answer first
  2. 17expert · hard

    An examiner is analyzing a USB drive that was used on both Windows and Linux systems. The drive is formatted with exFAT. The examiner finds a file that was deleted, but the file's directory entry is still present. Which aspect of exFAT allows the examiner to recover the file's metadata?

    Select an answer first
  3. 18application · medium

    A forensic examiner is analyzing a compromised Windows Server 2019 system. The examiner finds a scheduled task named 'WindowsUpdate' that runs a PowerShell script from C:\ProgramData\temp\update.ps1 every 5 minutes. The script downloads a payload from a remote server. The examiner wants to determine when this persistence mechanism was first established. Which artifact would provide the most reliable timeline for the creation of this scheduled task?

    Select an answer first
  4. 19foundation · easy

    During a forensic examination, you need to determine which websites a user visited using Google Chrome. Which browser artifact should you analyze?

    Select an answer first
  5. 20expert · hard

    An analyst is examining a Windows 10 system and finds an unknown application in the user's AppData\Roaming folder. The application's executable has a valid digital signature, but the signature was issued to a company that is known to be a shell company. The analyst also finds that the application creates a scheduled task at logon. Which finding would most strongly suggest the application is malicious?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.