
GIAC Certified Forensic Examiner
Domain 4Objective 1
System and Device Analysis GCFE Practice Questions (Page 9)
Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
9concepts
Questions 41–45
- 41
Which registry key is commonly analyzed to determine which programs run automatically at system startup?
Select an answer first - 42
Which type of data is most likely to be recoverable through file carving?
Select an answer first - 43
Which Windows registry hive contains information about the currently logged-on user's settings and activity?
Select an answer first - 44
What is a critical requirement for forensic reports to be admissible in court?
Select an answer first - 45
An examiner is analyzing a Windows 10 system and finds a shortcut file (.lnk) in the user's Startup folder. What can this indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.