Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 5Objective 2

macOS DFIR Fundamentals GEIR Practice Questions (Page 7)

Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
8concepts

Questions 31–35

  1. 31foundation · easy

    Which macOS directory is the root of the system volume and contains the standard top-level folders such as /Applications, /System, and /Users?

    Select an answer first
  2. 32foundation · easy

    Which macOS file format is commonly used to store application preferences and configuration data, and is a key forensic artifact?

    Select an answer first
  3. 33foundation · easy

    Which macOS artifact records system and application events in a unified manner and can be queried with the `log` command?

    Select an answer first
  4. 34foundation · easy

    Which macOS command is used to query the unified log for specific events, such as process launches or network connections?

    Select an answer first
  5. 35expert · hard

    An incident responder is examining a macOS system and needs to determine if a user account was recently created. The responder has access to the system and the user is logged in. Which artifact would provide the most reliable evidence of account creation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.