GIAC GIME Actual Free Exam Questions & Community Discussion
What type of data can be found in volatile memory on macOS devices?
Correct Answer: D
Vote an answer
What can be inferred from a consistent login pattern found during a "Pattern of Life" analysis?
Correct Answer: D
Vote an answer
How can an investigator use Unified Logs in macOS for timeline creation?
Correct Answer: A
Vote an answer
What is a crucial step in log analysis within incident response?
Correct Answer: B
Vote an answer
What aspect of user data is critical for distinguishing between different user profiles in system configuration analysis?
Correct Answer: D
Vote an answer
You are analyzing a macOS system involved in a data breach. The user is suspected of modifying system settings to avoid detection.
What steps will you take to identify changes in user settings and system configurations? (Choose three)
What steps will you take to identify changes in user settings and system configurations? (Choose three)
Correct Answer: A,B,C
Vote an answer
Which artifacts are commonly analyzed to reconstruct a user's pattern of life on macOS and iOS? (Select two)
Correct Answer: A,D
Vote an answer
Which macOS log files should be analyzed to track application crashes during forensic analysis?
Correct Answer: A
Vote an answer
What type of data can be extracted from the Maps application in iOS for forensic purposes?
Correct Answer: C
Vote an answer
Which command can you use to gather detailed system information about a macOS device during a triage?
Correct Answer: D
Vote an answer
In Apple Systems Triage, what artifact might show when the system was last managed or configured remotely?
Correct Answer: A
Vote an answer
For system triage, how can one identify the presence of network profiles?
Correct Answer: C
Vote an answer
0
0
0
10
