
GIAC Certified Forensic Examiner
Domain 2Objective 1
Forensic Artifact Techniques GCFE Practice Questions (Page 1)
Part of the Forensic Artifact Techniques domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
Questions 1–5
- 1
An examiner is preparing to image a hard drive from a suspect's computer. The examiner wants to ensure the evidence is admissible in court. Which of the following steps is MOST critical to maintain the integrity of the evidence?
Select an answer first - 2
What is the primary purpose of using a write blocker when acquiring forensic artifacts from a suspect's hard drive?
Select an answer first - 3
What is the primary reason for creating a cryptographic hash of a forensic image immediately after acquisition?
Select an answer first - 4
An examiner is investigating a case involving unauthorized access to a company's internal web application. The examiner has a forensic image of the web server and needs to identify which user accounts were accessed during the incident. Which artifact should the examiner examine to find this information?
Select an answer first - 5
An examiner is investigating a case of data theft where the suspect used a cloud storage client (e.g., Dropbox) on a Windows 10 system. The examiner needs to determine which files were uploaded to the cloud. Which of the following artifacts would be MOST useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.