Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 5Objective 2

macOS DFIR Fundamentals GEIR Practice Questions (Page 2)

Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
8concepts

Questions 6–10

  1. 6application · medium

    An incident responder finds a malicious application on a macOS system that was downloaded from the internet. The responder needs to determine whether Gatekeeper blocked or allowed the application to run. Which artifact provides this information?

    Select an answer first
  2. 7foundation · easy

    Which command-line tool on macOS is used to view and modify user accounts and groups?

    Select an answer first
  3. 8foundation · easy

    Which macOS persistence mechanism runs a program at system startup, before any user logs in, and is stored in /Library/LaunchDaemons?

    Select an answer first
  4. 9foundation · easy

    Which macOS feature encrypts the entire disk and requires a password or recovery key to unlock, impacting forensic acquisition?

    Select an answer first
  5. 10application · medium

    A forensic examiner is acquiring a MacBook Pro that has FileVault enabled. The examiner has the user's login password but does not have the recovery key. The Mac is currently powered off. What is the most appropriate acquisition approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.