
GIAC Certified Forensic Examiner
Domain 4Objective 1
System and Device Analysis GCFE Practice Questions (Page 7)
Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
9concepts
Questions 31–35
- 31
An examiner is investigating a Windows system and wants to identify when a specific executable was first run and how many times it has been executed. Which artifacts should be examined?
Select an answer first - 32
An examiner is investigating a Windows 10 system for evidence of unauthorized access. The examiner wants to determine if a user account was created and used, and also identify recently accessed documents. Which registry hives and keys should be examined?
Select an answer first - 33
An examiner has completed the analysis of a compromised system and is preparing the final report. The report must be understandable to non-technical stakeholders while preserving technical accuracy. What is the most appropriate approach?
Select an answer first - 34
An examiner has completed the analysis of a hard drive and needs to document the findings. Which element is essential to include in the forensic report to ensure the findings are reproducible?
Select an answer first - 35
Which activity falls within the scope of system and device analysis in digital forensics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.