
GIAC Certified Forensic Examiner
Domain 5Objective 1
File and Program Analysis GCFE Practice Questions (Page 8)
Part of the File and Program Analysis domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
10concepts
Questions 36–40
- 36
An examiner is investigating a case involving a Microsoft Outlook desktop client. The examiner needs to determine if a specific email was read by the user and when. Which artifact would provide the most direct evidence of the email being opened?
Select an answer first - 37
A file named 'invoice.pdf' is found on a suspect's drive. When you open it in a hex editor, the first bytes are 'MZ'. What does this indicate?
Select an answer first - 38
Which of the following is a reliable indicator that an application was installed on a Windows system?
Select an answer first - 39
During a memory analysis, you identify a suspicious process that is injecting code into a legitimate system process. Which memory artifact would provide the STRONGEST evidence of this injection?
Select an answer first - 40
On a Windows 10 system, which artifact is specifically designed to speed up the launch of applications and records the first time a program was executed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.