GIAC GIME Actual Free Exam Questions & Community Discussion
Which system configuration files are commonly analyzed during a macOS forensic investigation? (Select two)
Correct Answer: A,D
Vote an answer
What SQL clause is used to filter the results of a query?
Correct Answer: B
Vote an answer
During system triage, what indicates the initial installation date of the OS?
Correct Answer: C
Vote an answer
What artifact within the Apple File System indicates application usage?
Correct Answer: A
Vote an answer
Which acquisition method is preferred for preserving the integrity of data during an incident response?
Correct Answer: A
Vote an answer
During the analysis of user data from productivity applications, what is a primary focus?
Correct Answer: D
Vote an answer
Which data types can be recovered from a forensic image of an iOS device? (Select two)
Correct Answer: B,D
Vote an answer
In productivity application analysis, what data can be extracted from the Mail application?
Correct Answer: D
Vote an answer
Which tool is commonly used for memory acquisition on macOS devices?
Correct Answer: C
Vote an answer
During an investigation, you need to determine when a user typically uses their macOS device for online shopping.
What steps will you take to establish this pattern of life? (Choose three)
What steps will you take to establish this pattern of life? (Choose three)
Correct Answer: A,C,D
Vote an answer
What can iCloud data analysis reveal in a forensic context?
Correct Answer: D
Vote an answer
Which artifact indicates the OS backup frequency during system triage?
Correct Answer: C
Vote an answer
Which application's data would provide insights into the user's professional contacts and communications?
Correct Answer: D
Vote an answer
0
0
0
10
