
GIAC Enterprise Incident Responder
Domain 5Objective 2
macOS DFIR Fundamentals GEIR Practice Questions (Page 4)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
8concepts
Questions 16–20
- 16
An incident responder is examining a macOS system and needs to find the home directory of a specific user account. Which command or file will provide this information?
Select an answer first - 17
Which macOS directory contains the user account database and is a key location for examining local user accounts?
Select an answer first - 18
A security analyst needs to determine whether a specific application was launched on a macOS system and, if so, when. The application is not a standard Apple app. Which approach provides the most reliable evidence?
Select an answer first - 19
An analyst is investigating a macOS system and needs to determine if a specific process was running at a particular time in the past. Which command should the analyst use to query the unified log for process execution events?
Select an answer first - 20
An analyst needs to review authentication failures on a macOS system to identify a brute-force attack. Which command or tool provides the most direct access to this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.