
GIAC Certified Forensic Examiner
Domain 5Objective 1
File and Program Analysis GCFE Practice Questions (Page 6)
Part of the File and Program Analysis domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
10concepts
Questions 26–30
- 26
Which of the following artifacts is most likely to contain the content of instant messages sent and received on a Windows system?
Select an answer first - 27
You are examining a USB flash drive that was used to transfer files between Windows and macOS computers. Which file system would be most suitable for cross-platform compatibility and is commonly found on such drives?
Select an answer first - 28
An incident responder is performing live response on a compromised Windows system. The responder needs to identify a malicious process that is hiding from standard process listing tools. The responder suspects the process is using process hollowing. Which technique would be most effective in detecting this?
Select an answer first - 29
You are analyzing a file on a Windows system and need to determine which user account has read and write permissions to it. Which file metadata attribute should you examine?
Select an answer first - 30
In a forensic investigation, you need to determine when a specific document was last modified. Which file metadata attribute provides this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.