
GIAC Enterprise Incident Responder
Domain 5Objective 2
macOS DFIR Fundamentals GEIR Practice Questions (Page 7)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
8concepts
Questions 31–35
- 31
Which macOS directory is the root of the system volume and contains the standard top-level folders such as /Applications, /System, and /Users?
Select an answer first - 32
Which macOS file format is commonly used to store application preferences and configuration data, and is a key forensic artifact?
Select an answer first - 33
Which macOS artifact records system and application events in a unified manner and can be queried with the `log` command?
Select an answer first - 34
Which macOS command is used to query the unified log for specific events, such as process launches or network connections?
Select an answer first - 35
An incident responder is examining a macOS system and needs to determine if a user account was recently created. The responder has access to the system and the user is logged in. Which artifact would provide the most reliable evidence of account creation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.