Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 5Objective 2

macOS DFIR Fundamentals GEIR Practice Questions (Page 1)

Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
8concepts

Questions 1–5

  1. 1foundation · easy

    Which macOS artifact records the execution of applications, including the path and timestamp, and is often stored in a SQLite database?

    Select an answer first
  2. 2application · medium

    A forensic examiner is analyzing a macOS system and needs to determine when a specific file was last accessed. Which metadata attribute should the examiner examine?

    Select an answer first
  3. 3foundation · easy

    Which macOS file stores the list of previously connected Wi-Fi networks, including SSIDs and connection timestamps?

    Select an answer first
  4. 4expert · hard

    An analyst is investigating a macOS system where a process was launched by a launch agent, but the process is no longer running. The analyst needs to determine the exact command-line arguments used when the process was launched. Which artifact provides this information?

    Select an answer first
  5. 5foundation · easy

    Which macOS security feature protects system files and prevents even the root user from modifying them, and must be disabled to perform certain forensic acquisitions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.