
GIAC Enterprise Incident Responder
Domain 5Objective 2
macOS DFIR Fundamentals GEIR Practice Questions (Page 6)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
8concepts
Questions 26–30
- 26
During an incident response, an analyst finds a suspicious plist in /Library/LaunchDaemons. The plist is named com.example.malware.plist and contains a ProgramArguments key pointing to /tmp/update.sh. What is the most likely persistence mechanism?
Select an answer first - 27
During a forensic examination of a macOS system, you need to locate a user's Safari browsing history. The user account is named 'jsmith'. Which path contains this artifact?
Select an answer first - 28
A security analyst is investigating a macOS system and needs to determine if a specific application was launched from a USB drive. The application is no longer running. Which artifact would provide the most reliable evidence of the application's execution path?
Select an answer first - 29
Which macOS log file records a history of executed commands for each user, useful for determining user activity?
Select an answer first - 30
An incident responder needs to determine whether a specific process was running on a macOS system at a particular time in the past. The system has been rebooted since the suspected activity. Which approach provides the most reliable evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.