
GIAC iOS and macOS Examiner
Domain 4Objective 2
Incident Response GIME Practice Questions (Page 8)
Part of the Incident Response and Advanced Techniques domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
2concepts
Questions 36–38
- 36
A macOS system is suspected of being compromised. You have collected a memory dump, but you need to determine if any malicious code is injected into legitimate processes. Which analysis technique would be most effective?
Select an answer first - 37
During an iOS incident, you have a jailbroken device and need to determine if a malicious app is exfiltrating data. The app is currently running. You have limited time before the device must be returned to the user. Which action would provide the most comprehensive evidence within the time constraint?
Select an answer first - 38
A macOS system is suspected of running a keylogger. You need to identify the process responsible and any files it has created. Which approach would be most effective?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GIME
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.