
GIAC Enterprise Incident Responder
Domain 5Objective 1
macOS Essentials GEIR Practice Questions (Page 4)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 16–20
- 16
You need to review the unified log on a macOS system for events related to a specific process name 'malware' that occurred in the last hour. Which command should you use?
Select an answer first - 17
Which command-line tool is commonly used to read and convert property list files in macOS?
Select an answer first - 18
What is the primary purpose of FileVault on macOS?
Select an answer first - 19
An incident responder is investigating a Mac that may have been used to access a malicious IP address. The Mac's network configuration was changed after the incident, and the current IP address is different. The responder needs to determine the IP address that was in use at the time of the incident. Which approach would be most reliable?
Select an answer first - 20
Which directory is the standard location for LaunchDaemons that are installed by third-party software?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.