
GIAC Certified Forensic Examiner
Domain 4Objective 1
System and Device Analysis GCFE Practice Questions (Page 3)
Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
9concepts
Questions 11–15
- 11
An analyst is building a timeline of user activity on a Windows 7 system. The analyst wants to include evidence of programs that were run from USB drives and also identify when the user last accessed specific folders. Which artifacts should the analyst incorporate into the timeline?
Select an answer first - 12
An examiner is constructing a timeline of user activity on a Windows 10 system. Which artifacts should be included to provide the most comprehensive view of user actions?
Select an answer first - 13
An analyst is examining a FAT32 USB drive and finds that a deleted file's directory entry has been overwritten, but the file's data clusters are still present. What technique should the analyst use to recover the file?
Select an answer first - 14
An examiner is investigating a Windows 10 workstation. The user claims they never plugged in a specific USB drive. The examiner needs to determine if the drive was ever connected. Which registry hive and key should be examined to find evidence of USB device connections?
Select an answer first - 15
Which mobile device artifact is most likely to reveal the user's location history?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.