
GIAC iOS and macOS Examiner
Domain 4Objective 1
Apple Systems Triage GIME Practice Questions (Page 5)
Part of the Incident Response and Advanced Techniques domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 4–6 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
5concepts
Questions 21–25
- 21
During an incident response on a macOS workstation, you need to identify which local user account was used to log in around the time the OS was installed. You have access to the system logs and the user account database. Which combination of artifacts would provide the most reliable evidence of the first login after installation?
Select an answer first - 22
A macOS device is not receiving Wi-Fi network settings that are pushed by your MDM. You suspect a stale configuration profile is overriding the MDM payload. Which step would confirm this?
Select an answer first - 23
A forensic examiner needs to determine when the operating system was last reinstalled on a Mac and whether any user accounts were created after that date. Which combination of data sources would provide the most reliable evidence?
Select an answer first - 24
A macOS device is suspected of connecting to a corporate network via a VPN, but the VPN profile is not installed. You need to determine if the device used a VPN without a profile. Which artifact would be most useful?
Select an answer first - 25
On an iOS device, where can an examiner find the current IP address assigned to the device's Wi-Fi connection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.