
GIAC Enterprise Incident Responder
Domain 5Objective 1
macOS Essentials GEIR Practice Questions (Page 2)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 6–10
- 6
During an investigation, you need to determine which user accounts have administrative privileges on a macOS system. Which command or file should you consult?
Select an answer first - 7
A Mac is running a malicious process that is not persistent across reboots. The incident responder needs to identify the parent process that launched it and the command-line arguments used. Which command would provide the most comprehensive information?
Select an answer first - 8
What is the primary purpose of a property list (plist) file in macOS?
Select an answer first - 9
You are analyzing a macOS system where a user account appears to have been created by an attacker. The system has SIP enabled. Which of the following artifacts would provide the most reliable evidence of the account creation time?
Select an answer first - 10
A macOS system has a suspicious process that keeps restarting after being killed. You suspect a LaunchAgent or LaunchDaemon is responsible. Which directory should you check first for a user-level persistence mechanism?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.