Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC iOS and macOS Examiner

Domain 2Objective 1

Apple File System Artifacts GIME Practice Questions (Page 4)

Part of the Forensic Analysis and Artifacts domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
4concepts

Questions 16–20

  1. 16application · medium

    An examiner is analyzing a Mac that was used to log in, connect a USB drive, and then copy files. The examiner wants to establish the order of these events. Which artifacts would provide the most reliable sequence?

    Select an answer first
  2. 17application · medium

    A forensic analyst is reviewing a Mac that was used to access a confidential database. The analyst needs to determine which user accounts were logged in during the time of the suspected access. Which artifact would provide the most reliable login history?

    Select an answer first
  3. 18application · medium

    During an investigation, an examiner needs to determine when a specific PDF file was first created on a Mac. The file's creation date in the Finder is shown as 'January 15, 2024'. However, the examiner suspects the file was copied from an external source. Which artifact would help verify the original creation time?

    Select an answer first
  4. 19expert · hard

    An examiner is analyzing a macOS system where a user is suspected of searching for sensitive terms using Spotlight and then deleting the files that appeared in the results. The examiner has the Spotlight index and the APFS journal. The Spotlight index contains metadata for files that no longer exist on the system. The APFS journal shows the deletion of those files. Which of the following is the most likely interpretation?

    Select an answer first
  5. 20expert · hard

    An examiner is investigating a Mac where a user connected an external SSD and copied a large number of files. The examiner has the APFS journal from the external SSD, but the journal seems to contain only a few entries. The user is known to have used a tool that performs direct block-level copying. Which of the following is the most likely reason for the sparse journal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.