
GIAC Certified Forensic Examiner
Domain 4Objective 1
System and Device Analysis GCFE Practice Questions (Page 5)
Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
9concepts
Questions 21–25
- 21
A forensic examiner needs to extract call logs, SMS messages, and app data from an iPhone that is locked with a passcode. The device is running iOS 15 and has not been backed up to iCloud. What is the most appropriate acquisition method?
Select an answer first - 22
Which procedure is essential when acquiring data from a mobile device to maintain evidence integrity?
Select an answer first - 23
An examiner has completed the analysis of a mobile device and needs to document the findings. Which element is essential to include in the report to ensure the findings are admissible in court?
Select an answer first - 24
What is the primary purpose of Windows Prefetch files in forensic analysis?
Select an answer first - 25
An examiner is analyzing an NTFS volume and finds that the $MFT is corrupted. The examiner needs to recover files and build a timeline. What is the most appropriate approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.