
GIAC iOS and macOS Examiner
Domain 2Objective 2
Log Analysis and Timeline Creation GIME Practice Questions (Page 4)
Part of the Forensic Analysis and Artifacts domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
5concepts
Questions 16–20
- 16
During a forensic examination of a macOS system, which of the following is the primary source for system-level diagnostic messages, including kernel and driver events?
Select an answer first - 17
You are correlating logs from a macOS system and a network firewall. The firewall log shows a connection from the macOS system's IP address to an external server at 10:00:00. The macOS unified log shows a process making a network connection at 10:00:01. What is the most likely relationship?
Select an answer first - 18
Which of the following is the standard format for the unified logging system on macOS?
Select an answer first - 19
An examiner is analyzing an iOS device and needs to locate logs related to a specific app's data synchronization. The examiner has access to the device's unified log, a plist file from the app, and a SQLite database from the app. Which log sources are most likely to contain synchronization timestamps? Select all that apply.
Select an answer first - 20
When correlating log entries from multiple sources, which field is most commonly used to establish a coherent event sequence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.