
GIAC Enterprise Incident Responder
Domain 5Objective 2
macOS DFIR Fundamentals GEIR Practice Questions (Page 3)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
8concepts
Questions 11–15
- 11
Which macOS persistence mechanism runs a program automatically when a user logs in, and is stored in /Library/LaunchAgents or ~/Library/LaunchAgents?
Select an answer first - 12
An incident responder needs to acquire forensic evidence from a MacBook Pro that has FileVault enabled. The device is currently powered on and the user is logged in. Which acquisition approach is most appropriate in this scenario?
Select an answer first - 13
A macOS user reports that a suspicious process named 'updatehelper' launches every time they log in, even after they quit it. During triage, you confirm the process is not a standard Apple binary. Which location should you examine FIRST to identify the mechanism responsible for this behavior?
Select an answer first - 14
An incident responder needs to acquire a forensic image of a macOS system's SSD. The system has FileVault enabled and the responder has the recovery key. The system is powered off. Which acquisition method will produce a decrypted image?
Select an answer first - 15
Which macOS logging system, introduced in macOS Sierra, consolidates system and application logs into a centralized store?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.