
GIAC Enterprise Incident Responder
Domain 5Objective 2
macOS DFIR Fundamentals GEIR Practice Questions (Page 2)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
8concepts
Questions 6–10
- 6
An incident responder finds a malicious application on a macOS system that was downloaded from the internet. The responder needs to determine whether Gatekeeper blocked or allowed the application to run. Which artifact provides this information?
Select an answer first - 7
Which command-line tool on macOS is used to view and modify user accounts and groups?
Select an answer first - 8
Which macOS persistence mechanism runs a program at system startup, before any user logs in, and is stored in /Library/LaunchDaemons?
Select an answer first - 9
Which macOS feature encrypts the entire disk and requires a password or recovery key to unlock, impacting forensic acquisition?
Select an answer first - 10
A forensic examiner is acquiring a MacBook Pro that has FileVault enabled. The examiner has the user's login password but does not have the recovery key. The Mac is currently powered off. What is the most appropriate acquisition approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.