
GIAC Certified Forensic Examiner
Domain 4Objective 1
System and Device Analysis GCFE Practice Questions (Page 8)
Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
9concepts
Questions 36–40
- 36
In digital forensics, what is the primary objective of system and device analysis?
Select an answer first - 37
An examiner is investigating a Windows system and finds that the prefetch files have been deleted. The examiner needs to determine which programs were executed. Which combination of artifacts should the examiner use to recover execution evidence?
Select an answer first - 38
Which data source is commonly used to build a timeline of system activity?
Select an answer first - 39
An examiner is acquiring data from a mobile device that is powered off. Which acquisition method should be used to preserve the most data?
Select an answer first - 40
What is the primary difference between logical and physical extraction in mobile device forensics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.