Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Examiner

Domain 5Objective 1

File and Program Analysis GCFE Practice Questions (Page 8)

Part of the File and Program Analysis domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
10concepts

Questions 36–40

  1. 36application · medium

    An examiner is investigating a case involving a Microsoft Outlook desktop client. The examiner needs to determine if a specific email was read by the user and when. Which artifact would provide the most direct evidence of the email being opened?

    Select an answer first
  2. 37foundation · easy

    A file named 'invoice.pdf' is found on a suspect's drive. When you open it in a hex editor, the first bytes are 'MZ'. What does this indicate?

    Select an answer first
  3. 38foundation · easy

    Which of the following is a reliable indicator that an application was installed on a Windows system?

    Select an answer first
  4. 39expert · hard

    During a memory analysis, you identify a suspicious process that is injecting code into a legitimate system process. Which memory artifact would provide the STRONGEST evidence of this injection?

    Select an answer first
  5. 40foundation · easy

    On a Windows 10 system, which artifact is specifically designed to speed up the launch of applications and records the first time a program was executed?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.