
GIAC Enterprise Incident Responder
Domain 5Objective 1
macOS Essentials GEIR Practice Questions (Page 5)
Part of the macOS Forensics domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 5–9 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 21–25
- 21
Which file in macOS stores the DNS resolver configuration?
Select an answer first - 22
You are investigating a macOS system that was compromised. The attacker likely used a legitimate system tool to exfiltrate data over the network. You need to determine which tool was used and when. The system has unified logging enabled. Which approach would provide the most comprehensive evidence?
Select an answer first - 23
You are investigating a Mac where a user downloaded an application from the internet, but Gatekeeper blocked it. You need to determine why it was blocked and whether the user bypassed the protection. Which files or logs would you examine?
Select an answer first - 24
A Mac is running a process that is not visible in Activity Monitor but is consuming CPU. You suspect a LaunchDaemon. Which command would you use to list all running processes, including those of other users and system processes, to identify the culprit?
Select an answer first - 25
An incident responder needs to determine if a Mac was connected to a specific Wi-Fi network at a given time. Which log source would provide the most reliable evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.