
GIAC Foundational Cybersecurity Technologies
Domain 6Objective 2
Forensics & Post-Exploitation GFACT Practice Questions (Page 3)
Part of the Offensive Security and Defense domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 11–15
- 11
During a forensic investigation, an analyst needs to create a bit-for-bit copy of a suspect's hard drive to preserve the original evidence. Which tool is commonly used for this purpose?
Select an answer first - 12
An attacker has compromised a Windows workstation and wants to access another system using the same credentials without knowing the plaintext password. Which lateral movement technique enables this?
Select an answer first - 13
After successfully exploiting a vulnerability, an attacker's primary goal is often to maintain persistent access to the compromised system. Which post-exploitation activity directly supports this goal?
Select an answer first - 14
A company has suffered a data breach. The incident response team has identified the attacker's entry point and has contained the affected systems. The team is now in the eradication phase. Which action is most appropriate during this phase?
Select an answer first - 15
An attacker has compromised a server and wants to access other systems on the network to expand their control. What is the primary purpose of lateral movement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GFACT” is a trademark of its owner, used for identification only.