Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC iOS and macOS Examiner

Domain 1Objective 1

Introduction to Apple Operating Systems GIME Practice Questions (Page 2)

Part of the Apple Operating System Fundamentals domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
1concept

Questions 6–10

  1. 6application · medium

    A forensic examiner is asked to acquire evidence from a macOS system that is part of a corporate network. The system is currently powered off. The examiner needs to preserve the integrity of the evidence and ensure that the acquisition process does not alter any data on the drive. Which acquisition method is most appropriate?

    Select an answer first
  2. 7application · medium

    An examiner is asked to analyze a Mac that was used to create a document that was later deleted. The examiner needs to recover the document's content. The system has been powered off for two days. Which data source is most likely to contain the deleted document?

    Select an answer first
  3. 8application · medium

    A forensic examiner is called to acquire evidence from a macOS system that is part of a legal investigation. The system is running and the user is present. The examiner needs to ensure that the acquisition is legally defensible and does not alter any evidence. Which action is most appropriate?

    Select an answer first
  4. 9application · medium

    A company's security team needs to collect evidence from a macOS system that is suspected of being used to exfiltrate sensitive documents. The system is currently running, and the user is away. The team wants to preserve the state of the system for later analysis, including any running processes and network connections. Which action should the team take first?

    Select an answer first
  5. 10application · medium

    During an incident response, an examiner needs to determine whether a user ran a specific command in the Terminal and what files were accessed around that time. The system is still running. Which combination of data sources would provide the most relevant evidence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.