Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Examiner

Domain 4Objective 1

System and Device Analysis GCFE Practice Questions (Page 2)

Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
9concepts

Questions 6–10

  1. 6foundation · easy

    What is the recommended first step when acquiring evidence from a powered-on Windows computer?

    Select an answer first
  2. 7foundation · easy

    What is file carving in digital forensics?

    Select an answer first
  3. 8application · medium

    An examiner is analyzing a Windows 10 system and finds a .lnk file in the user's Recent Items folder that points to a document on a network share. What can this artifact indicate about user activity?

    Select an answer first
  4. 9foundation · easy

    Which element should be included in a forensic report to allow another examiner to reproduce the analysis?

    Select an answer first
  5. 10application · medium

    During a forensic examination of an NTFS volume, the analyst finds that a file's MFT entry indicates the file is active, but the file's data runs point to clusters that are marked as unallocated. What does this indicate, and what should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.