Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free GIAC Certified Forensics Analyst GCFA Exam Questions

Page: 1 / 22 Total 330 questions

Want more questions? Get Premium Access.

Question 1

Which of the following statements about SD cards are true?

Each correct answer represents a complete solution. Choose two.

Correct Answer: A. It is used with mobile phones and digital cameras.; B. It is a type of non-volatile memory card.

Question 2

Mark works as a security manager for SofTech Inc. He is using a technique for monitoring what the employees are doing with corporate resources. Which of the following techniques is being used by Mark to gather evidence of an ongoing computer crime if a member of the staff is e-mailing company's secrets to an opponent?

Correct Answer: A. Electronic surveillance

Question 3

Which of the following articles defines illegal access to the computer or network in Chapter 2 of Section 1, i.e., Substantive criminal law of the Convention on Cybercrime passed by the Council of Europe?

Correct Answer: A. Article 2

Question 4

Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate the main server of SecureEnet Inc. The server runs on Debian Linux operating system. Adam wants to investigate and review the GRUB configuration file of the server system.

Which of the following files will Adam investigate to accomplish the task?

Correct Answer: A. /boot/grub/menu.lst

Question 5

Which of the following files in LILO booting process of Linux operating system stores the location of Kernel on the hard drive?

Correct Answer: A. /boot/map

Question 6

Which of the following tools is an asterisk password revealer tool?

Correct Answer: B. SnadBoy

Question 7

Which of the following is a correct sequence of different layers of Open System Interconnection (OSI) model?

Correct Answer: C. Physical layer, data link layer, network layer, transport layer, session layer, presentation layer, and application layer

Question 8

Which of the following steps should be performed in order to optimize a system performance?

Each correct answer represents a complete solution. Choose three.

Correct Answer: A. Run anti-spyware program regularly; B. Defragment the hard disk drive; D. Delete the temporary files

Question 9

Which of the following sections of an investigative report covers the background and summary of the report including the outcome of the case and the list of allegations?

Correct Answer: A. Section 2

Question 10

Which of the following tools can be used to perform tasks such as Windows password cracking, Windows enumeration, and VoIP session sniffing?

Correct Answer: D. Cain

Question 11

Which of the following anti-child pornography organizations helps local communities to create

programs and develop strategies to investigate child exploitation?

Correct Answer: B. Project Safe Childhood (PSC)

Question 12

What is the name of the group of blocks which contains information used by the operating system in Linux system?

Correct Answer: D. Superblock

Question 13

Peter works as a Computer Hacking Forensic Investigator for SecureEnet Inc. He has been assigned with a project of investigating a disloyal employee who is accused of stealing secret data from the company and selling it to the competitor company. Peter is required to collect proper evidences and information to present before the court for prosecution. Which of the following parameters is necessary for successful prosecution of this corporate espionage?

Correct Answer: A. To prove that the information has a value.

Question 14

Which of the following tools is used to extract human understandable interpretation from the computer binary files?

Correct Answer: B. Word Extractor

Question 15

Rick works as a Network Administrator for uCertify Inc. He takes a backup of some important

compressed files on an NTFS partition, using the Windows 2000 Backup utility. Rick restores these files in a FAT32 partition. He finds that the restored files do not have the compression attribute. What is the most likely cause?

Correct Answer: A. A FAT32 partition does not support compression.