
GIAC iOS and macOS Examiner
Domain 4Objective 3
Encrypted Container and Memory Analysis GIME Practice Questions (Page 1)
Part of the Incident Response and Advanced Techniques domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 4–6 from this objective — we provide 10 practice questions to prepare you well beyond it. (estimate)
10questions here
2free pages
2concepts
Questions 1–5
- 1
An examiner has a memory image from an iOS device and wants to extract the encryption keys for the Keychain. Which approach is most effective?
Select an answer first - 2
An examiner has an encrypted APFS volume and a password hint that says the password is a common phrase with a number at the end. The examiner has a wordlist of common phrases. Which attack mode is most efficient?
Select an answer first - 3
What is a key strategy when using brute-force techniques to access encrypted data on a macOS system?
Select an answer first - 4
An examiner wants to acquire memory from an iOS device. Which approach is a known limitation of iOS memory acquisition?
Select an answer first - 5
An examiner has a macOS system with FileVault enabled. The user's password is unknown, but the examiner has a list of possible passwords. Which tool is most appropriate to attempt to unlock the FileVault volume?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.