
GIAC Certified Forensic Examiner
Domain 2Objective 1
Forensic Artifact Techniques GCFE Practice Questions (Page 5)
Part of the Forensic Artifact Techniques domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 7–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
Questions 21–25
- 21
A forensic examiner needs to acquire the contents of a USB drive that was used to exfiltrate data. The drive is connected to a Windows 10 system that is currently running. Which acquisition method best preserves the evidentiary value of the drive?
Select an answer first - 22
An examiner is preparing a report for a case involving alleged intellectual property theft. The examiner needs to document the analysis of a suspect's computer, including the recovery of deleted files. Which of the following is the MOST appropriate way to document the recovery of deleted files?
Select an answer first - 23
An examiner is documenting the analysis of a suspect's chat logs. The examiner used a third-party tool to parse the logs. What is the most important information to include in the documentation?
Select an answer first - 24
What is the primary purpose of maintaining a chain of custody document during a forensic examination?
Select an answer first - 25
An examiner is preserving evidence from a Windows 10 system that is part of a civil litigation. The opposing counsel has requested that the original hard drive be produced. What is the most appropriate response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.