
GIAC Certified Forensic Examiner
Domain 6Objective 1
User Artifact Analysis GCFE Practice Questions (Page 1)
Part of the User and Cloud Artifacts domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 1–5
- 1
A user is suspected of using private browsing mode in Chrome to hide web activity. The examiner needs to determine if any evidence of the user's browsing remains. Which artifact would be most likely to contain remnants of private browsing activity?
Select an answer first - 2
Which registry key is specifically designed to track programs and files that a user has executed or opened?
Select an answer first - 3
A user is suspected of using Google Drive to exfiltrate files. Which combination of artifacts would best help you determine which files were uploaded to Google Drive from the user's Windows system?
Select an answer first - 4
During a Windows forensic examination, which of the following is considered a user artifact that can provide evidence of user activity?
Select an answer first - 5
During an investigation, you need to determine whether a user deleted a specific file from an NTFS volume. The file's $MFT entry is no longer present. Which artifact would be most useful to establish that the file existed and was deleted?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.