GIAC Forensics Examiner Practice Test - GCFE FREE EXAM DUMPS QUESTIONS & ANSWERS
During a forensic investigation, you need to determine if unauthorized software was installed on a computer. Which event logs would be most useful to analyze to confirm this activity? (Choose three)
Correct Answer: A,D,E
Vote an answer
What role do 'system snapshots' play in forensic analysis of file activities?
Correct Answer: A
Vote an answer
How do forensic analysts use the information from 'system snapshots' in their investigations?
Correct Answer: A
Vote an answer
The Windows Recycle Bin stores deleted file metadata in which file?
Correct Answer: B
Vote an answer
How do forensic investigators use slack space to recover data?
Correct Answer: A
Vote an answer
What type of forensic artifact can be derived from the browser's download history?
Correct Answer: A
Vote an answer
Which of the following is most useful for identifying manually typed URLs in a browser forensic investigation?
Correct Answer: B
Vote an answer
How can the analysis of browser sync data aid in forensic investigations?
Correct Answer: C
Vote an answer
What is the purpose of using 'timeline analysis' in forensic investigations?
Correct Answer: B
Vote an answer
What type of information does the analysis of API call logs from cloud storage providers typically yield?
Correct Answer: C
Vote an answer