GIAC GCFE Certification Sample Questions

GCFE Dumps, GCFE PDF, GCFE VCE, GIAC Certified Forensic Examiner VCE, GIAC GCFE PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Certified Forensic Examiner (GCFE) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GCFE certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GCFE Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Certified Forensic Examiner (GCFE) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Certified Forensic Examiner exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GCFE Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GCFE Sample Questions:

01. For an e-Discovery hold, counsel asks whether custodian mlopez had a persistent drive letter mapped to the finance share \\fs01\finance, and which letter it was. The examiner has her NTUSER.DAT and the system hives.
Which location records that mapping?
a) SYSTEM\MountedDevices, in the \DosDevices\ value for each drive letter
b) NTUSER.DAT\Network, in the RemotePath value under a subkey named for the letter
c) SOFTWARE\...\NetworkList\Profiles, in the ProfileName value recorded for each network that the laptop joined
d) NTUSER.DAT\...\Explorer\TypedPaths, in the url values for typed locations
 
02. On a law-enforcement image of a suspect's laptop, investigators believe he opened ledger.xlsx straight from inside payments.zip by double-clicking it in File Explorer, without extracting the archive. The archive is still in his Downloads folder.
Which two findings would support that account of events?
(Choose two.)
a) A Prefetch file for the third-party archive utility that opened payments.zip
b) An Amcache.hve entry recording payments.zip with its SHA-1 hash
c) Shellbag entries showing payments.zip was browsed as a folder
d) $UsnJrnl:$J records showing payments.zip was read at that time
e) A Recent LNK for ledger.xlsx whose target lies in a temporary folder named after payments.zip
 
03. Under an e-Discovery hold, a custodian's project files were kept on D:, a second internal NTFS drive in her workstation. The examiner finds no $I records with D:\ paths in C:\$Recycle.Bin under her SID.
Where should the examiner look next for her deletions of those files?
a) Nowhere, as files deleted from a second drive skip the bin
b) D:\$Recycle.Bin under her SID, since each fixed NTFS volume keeps its own bin
c) The BitBucket key in her NTUSER.DAT, which stores deleted D: items
d) C:\$Recycle.Bin\S-1-5-18, where SYSTEM holds other volumes' items
 
04. Which hash set is used to filter out known operating-system and commercial application files, so that review can focus on everything else?
a) A known-bad hash set from prior cases
b) The Amcache SHA-1 values from the image
c) The NSRL Reference Data Set
d) VirusTotal hash lookups
 
05. Network staff link cryptomining traffic to internal address 10.40.12.87 yesterday afternoon. From a laptop's registry, the examiner wants the address the laptop most recently obtained by DHCP and when that lease began.
Which key records this?
a) SOFTWARE\...\NetworkList\Signatures, beside each gateway MAC
b) SYSTEM\...\Tcpip\Parameters\Interfaces, under the adapter's GUID subkey
c) SOFTWARE\...\NetworkList\Profiles, beside each network's first and last connection dates
d) SYSTEM\...\Control\ComputerName, in the ComputerName value
 
06. In a timekeeping dispute, an employee says he did no work before 09:00 local time on 4 March 2026. His laptop is set to Eastern Standard Time (UTC-5), and a parsed Timeline row from his account's ActivitiesCache.db reads:
App: EXCEL.EXE | DisplayText: overtime-claims.xlsx | StartTime: 1772629500 | EndTime: 1772632920
What does this row show?
a) Activity on the file from 08:05 to 09:02 local time, in his account
b) Activity on the file from 13:05 to 14:02 local time
c) Only that the file was saved at 09:02, since EndTime records the last save to disk
d) Nothing datable, since these are FILETIME counts
 
07. A policy-violation audit finds that a nightly scheduled task on a design workstation launched an unapproved file-sync utility. Only the Microsoft-Windows-TaskScheduler/Operational log was exported from the image.
Which two records in that log would show the task being registered and the task launching its program?
(Choose two.)
a) Event 141, recording that a task registration was deleted
b) Event 200, recording that the task launched its action
c) Event 7045, recording that a service was installed, with its image path
d) Event 4698, recording that a scheduled task was created, with its XML definition
e) Event 106, recording that a user registered the task
 
08. Reviewing a contractor's returned laptop, an examiner's Recycle Bin parser reports a header version of 2 for each $I record it reads.
What does version 2 indicate about these records?
a) A Windows 10 layout, with a path-length field before a variable-length path
b) The files were restored once from the bin
c) The records are the legacy INFO2 format, carried over from an old Windows XP upgrade
d) Each item was deleted twice, and the record keeps only the second deletion time
 
09. During an HR misconduct inquiry, an examiner notices that a workstation's Application log begins only minutes before collection.
Which record would show that the Application log was cleared?
a) Security event 1102, recorded when the audit log is cleared
b) System event 6006, recorded when the Event Log service stops
c) Security event 4719, recorded when the audit policy changes
d) System event 104, which names the cleared log and the account that cleared it
 
10. On a law-enforcement image of a suspect's laptop, a detective's report quotes an Event Viewer screenshot showing a 4624 at 09:14. The screenshot was taken on a station set to US Eastern time (UTC-5 in January). The parsed record's TimeCreated is 2026-01-12 14:14:33 UTC, and the laptop's TimeZoneInformation is Pacific Standard Time (UTC-8 in January).
At what laptop-local time did the logon occur?
a) 22:14, since the eight-hour Pacific offset is added to UTC
b) 14:14, since event records store the local time of the system that wrote them
c) 06:14, since the record holds UTC and the screenshot showed the viewer's own zone
d) 09:14, since Event Viewer displays times in the zone of the computer that logged the event

Answers:

Question: 01
Answer: b
Question: 02
Answer: c, e
Question: 03
Answer: b
Question: 04
Answer: c
Question: 05
Answer: b
Question: 06
Answer: a
Question: 07
Answer: b, e
Question: 08
Answer: a
Question: 09
Answer: d
Question: 10
Answer: c

Note: For any error in GIAC Certified Forensic Examiner (GCFE) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.9 / 5 (111 votes)