
GIAC Enterprise Incident Responder
Domain 5Objective 1
macOS Essentials GEIR Practice Questions (Page 3)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 11–15
- 11
A user reports that their Mac was compromised and the attacker may have created a new account. During triage, you need to quickly identify any recently created user accounts and their home directories. Which command or file would provide the most direct evidence of account creation timestamps and home directory paths?
Select an answer first - 12
You are responding to an incident where a macOS system was used to perform a port scan of the internal network. The system has since been rebooted. Which of the following artifacts would provide the best evidence of the scanning activity?
Select an answer first - 13
You are examining a macOS system and need to find the user's network configuration preferences, such as which Wi-Fi networks they have joined. Which directory or file should you examine?
Select an answer first - 14
During a forensic examination, you need to find evidence of a user's recently accessed files and folders. Which file or database would provide the most direct evidence of recently opened documents?
Select an answer first - 15
What is the primary purpose of the keychain in macOS?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.