
GIAC Enterprise Incident Responder
Domain 5Objective 1
macOS Essentials GEIR Practice Questions (Page 1)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 1–5
- 1
What is the role of System Integrity Protection (SIP) in macOS?
Select an answer first - 2
During a forensic acquisition of a Mac, you find that the user's home directory is encrypted with FileVault. You have the user's password. What is the most appropriate way to acquire the user's data while preserving the integrity of the encrypted volume?
Select an answer first - 3
An incident responder needs to capture the current network configuration of a Mac that is suspected of using a rogue DHCP server. Which command would show the IP address, subnet mask, router, and DHCP server address in a single output?
Select an answer first - 4
Which command-line tool is used to display and manipulate network interfaces in macOS?
Select an answer first - 5
You are analyzing a macOS system and need to find evidence of applications that launched at login. Which file or directory should you examine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.