GIAC GIME Actual Free Exam Questions & Community Discussion

  • Exam Code/Number: GIME
  • Exam Name/Title: GIAC iOS and macOS Examiner
  • Certification Provider: GIAC
  • Corresponding Certification: Digital Forensics
  • Exam Questions: 157
  • Updated On: Jun 02, 2026
Which system configuration files are commonly analyzed during a macOS forensic investigation? (Select two)
Correct Answer: A,D Vote an answer
What SQL clause is used to filter the results of a query?
Correct Answer: B Vote an answer
During system triage, what indicates the initial installation date of the OS?
Correct Answer: C Vote an answer
What artifact within the Apple File System indicates application usage?
Correct Answer: A Vote an answer
Which acquisition method is preferred for preserving the integrity of data during an incident response?
Correct Answer: A Vote an answer
During the analysis of user data from productivity applications, what is a primary focus?
Correct Answer: D Vote an answer
Which data types can be recovered from a forensic image of an iOS device? (Select two)
Correct Answer: B,D Vote an answer
In productivity application analysis, what data can be extracted from the Mail application?
Correct Answer: D Vote an answer
Which tool is commonly used for memory acquisition on macOS devices?
Correct Answer: C Vote an answer
During an investigation, you need to determine when a user typically uses their macOS device for online shopping.
What steps will you take to establish this pattern of life? (Choose three)
Correct Answer: A,C,D Vote an answer
What can iCloud data analysis reveal in a forensic context?
Correct Answer: D Vote an answer
Which artifact indicates the OS backup frequency during system triage?
Correct Answer: C Vote an answer
Which application's data would provide insights into the user's professional contacts and communications?
Correct Answer: D Vote an answer
0
0
0
10