
GIAC Enterprise Incident Responder
Domain 5Objective 2
macOS DFIR Fundamentals GEIR Practice Questions (Page 8)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
8concepts
Questions 36–39
- 36
During an investigation, an analyst needs to find recently modified files on a macOS system that may be related to malware activity. The analyst has admin access and the system is running. Which approach is most effective?
Select an answer first - 37
An incident responder needs to acquire forensic evidence from a macOS system with FileVault enabled. The system is powered off and the responder has the user's password but not the recovery key. Which acquisition method will successfully obtain decrypted data?
Select an answer first - 38
A security analyst is investigating a macOS system where a malicious binary was executed. The analyst needs to determine the exact command-line arguments used when the process was launched. Which artifact provides this information?
Select an answer first - 39
During an investigation, you need to determine which Wi-Fi networks a macOS system connected to in the past 30 days. The system is currently online and the user is present. Which approach provides the most direct evidence of historical Wi-Fi connections?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GEIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.