Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC iOS and macOS Examiner

Domain 2Objective 1

Apple File System Artifacts GIME Practice Questions (Page 2)

Part of the Forensic Analysis and Artifacts domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
4concepts

Questions 6–10

  1. 6foundation · easy

    What type of information can be recovered from Spotlight index files during a forensic examination?

    Select an answer first
  2. 7application · medium

    An analyst is examining a Mac that was used to access sensitive documents. The user cleared the Finder's 'Recent Items' and deleted the documents. The analyst needs to recover evidence of the file names and the times they were accessed. Which artifact would be most useful?

    Select an answer first
  3. 8expert · hard

    An examiner is investigating a Mac where a user allegedly deleted incriminating files and then connected a USB drive. The examiner has the following evidence: (1) The file system journal shows the files were deleted at 10:00 AM. (2) The unified log shows a USB drive was connected at 10:05 AM. (3) The user's login history shows they logged in at 9:55 AM. The examiner needs to determine if the user could have copied the files to the USB drive before deleting them. Which conclusion is most defensible?

    Select an answer first
  4. 9application · medium

    An administrator needs to audit system configuration changes on a Mac, such as changes to network settings or user accounts. Which artifact would provide a comprehensive history of these changes?

    Select an answer first
  5. 10expert · hard

    An examiner is analyzing a macOS system where a user is suspected of using a VPN to hide their activity. The examiner wants to determine if the user accessed a specific file during a VPN session. The system's unified log shows the VPN connection, but the APFS journal does not show any file access during that time. The Spotlight index shows the file was accessed at a time that overlaps with the VPN session. Which of the following is the most likely explanation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.