GIAC GCFE Actual Free Exam Questions & Community Discussion
Why is live data acquisition important in some forensic investigations?
Correct Answer: C
Vote an answer
How do SMTP headers contribute to email forensic analysis? (Choose Two)
Correct Answer: C,D
Vote an answer
What role does examining the attachment metadata play in email forensic analysis? (Choose Three)
Correct Answer: A,D,E
Vote an answer
When analyzing browser data in Google Chrome, which files are useful for understanding download history? (Choose Two)
Correct Answer: A,E
Vote an answer
When examining browser artifacts, which of the following files are crucial for reconstructing a user's search history? (Choose Two)
Correct Answer: A,C
Vote an answer
In forensic investigations, why is the analysis of 'temporary files' crucial?
Correct Answer: A
Vote an answer
What is the primary purpose of creating a forensic image of a hard drive?
Correct Answer: C
Vote an answer
How can an analyst use 'security logs' to detect unauthorized access attempts?
Correct Answer: B
Vote an answer
What is the forensic value of analyzing the 'Windows Event Viewer' in the context of system analysis?
Correct Answer: B
Vote an answer
How can 'scheduled tasks' in a user profile indicate malicious activity?
Correct Answer: B
Vote an answer
What is the purpose of using 'timeline analysis' in forensic investigations?
Correct Answer: C
Vote an answer
You are tasked with collecting evidence from a running system suspected of being involved in a cyberattack. Which steps should you prioritize to preserve volatile data while ensuring data integrity? (Choose three)
Correct Answer: A,C,D
Vote an answer
Which Windows log is typically used to track application crashes or failures?
Correct Answer: C
Vote an answer
Why is it important to analyze the 'Outbox' and 'Drafts' folders in an email forensic investigation?
Correct Answer: A
Vote an answer
0
0
0
10
