[Jun-2023] GCFA Pre-Exam Practice Tests Exam Questions and Answers for GIAC Information Security Study Guide [Q114-Q136]

Share

[Jun-2023] GCFA Pre-Exam Practice Tests | Exam Questions and Answers for GIAC Information Security Study Guide

GIAC Certified Forensics Analyst Certification Sample Questions


Topics Tested in GCFA Evaluation

When they decide to take the GCFA test, the candidates should check carefully the topics included in the blueprint. Any individual who manages to demonstrate the following acumen will have higher chances to pass the GCFA exam from the first attempt:

  • Identifying any abnormal activity in Windows memory’s structure and immediately identifying different types of artifacts like suspicious drivers or malicious processes;
  • Demonstrating that he/she knows how to manage the structure file system associated with Windows infrastructure;
  • Getting the gist of is the techniques that a specialist should take to document the user’s activity and quickly identify the difference between an abnormal and normally working system;
  • Demonstrating how to choose the right moment for collecting the timeline data when operating in a Windows system;

 

NEW QUESTION # 114
Peter works as a Computer Hacking Forensic Investigator for SecureEnet Inc. He has been assigned with a project of investigating a disloyal employee who is accused of stealing secret data from the company and selling it to the competitor company. Peter is required to collect proper evidences and information to present before the court for prosecution. Which of the following parameters is necessary for successful prosecution of this corporate espionage?

  • A. To prove that the information has a value.
  • B. To prove that the data belongs to the company.
  • C. To submit investigative report to senior officials.
  • D. To present the evidences before the court.

Answer: A


NEW QUESTION # 115
Which of the following tools can be used to perform a whois query?
Each correct answer represents a complete solution. Choose all that apply.

  • A. WsPingPro
  • B. Sam Spade
  • C. SuperScan
  • D. Traceroute

Answer: A,B,C


NEW QUESTION # 116
A Web-based credit card company had collected financial and personal details of Mark before issuing him a credit card. The company has now provided Mark's financial and personal details to another company. Which of the following Internet laws has the credit card issuing company violated?

  • A. Security law
  • B. Privacy law
  • C. Copyright law
  • D. Trademark law

Answer: B


NEW QUESTION # 117
You work as a Network Administrator for Blue Bell Inc. You want to install Windows XP Professional on your computer, which already has Windows Me installed. You want to configure your computer to dual boot between Windows Me and Windows XP Professional. You have a single 40GB hard disk.
Which of the following file systems will you choose to dual-boot between the two operating systems?

  • A. NTFS
  • B. FAT
  • C. CDFS
  • D. FAT32

Answer: D


NEW QUESTION # 118
Which of the following tools is used to extract human understandable interpretation from the computer binary files?

  • A. Word Extractor
  • B. FTK Imager
  • C. FAU
  • D. Galleta

Answer: A

Explanation:
Section: Volume B


NEW QUESTION # 119
Which of the following anti-child pornography organizations helps local communities to create programs and develop strategies to investigate child exploitation?

  • A. Internet Crimes Against Children (ICAC)
  • B. Innocent Images National Imitative (IINI)
  • C. Anti-Child Porn.org
  • D. Project Safe Childhood (PSC)

Answer: D


NEW QUESTION # 120
Adam works as a professional Computer Hacking Forensic Investigator, a project has been assigned to him to investigate and examine files present on suspect's computer. Adam uses a tool with the help of which he can examine recovered deleted files, fragmented files, and other corrupted data. He can also examine the data, which was captured from the network, and access the physical RAM, and any processes running in virtual memory with the help of this tool. Which of the following tools is Adam using?

  • A. WinHex
  • B. Vedit
  • C. HxD
  • D. Evidor

Answer: A


NEW QUESTION # 121
Which of the following is a name, symbol, or slogan with which a product is identified?

  • A. Trade secret
  • B. Trademark
  • C. Patent
  • D. Copyright

Answer: B


NEW QUESTION # 122
Adam works as a Computer Hacking Forensic Investigator for a garment company in the United States. A project has been assigned to him to investigate a case of a disloyal employee who is suspected of stealing design of the garments, which belongs to the company and selling those garments of the same design under different brand name. Adam investigated that the company does not have any policy related to the copy of design of the garments. He also investigated that the trademark under which the employee is selling the garments is almost identical to the original trademark of the company. On the grounds of which of the following laws can the employee be prosecuted?

  • A. Cyber law
  • B. Espionage law
  • C. Trademark law
  • D. Copyright law

Answer: C

Explanation:
Section: Volume A


NEW QUESTION # 123
Which of the following is the correct order of digital investigations Standard Operating Procedure (SOP)?

  • A. Initial analysis, request for service, data collection, data analysis, data reporting
  • B. Request for service, initial analysis, data collection, data reporting, data analysis
  • C. Initial analysis, request for service, data collection, data reporting, data analysis
  • D. Request for service, initial analysis, data collection, data analysis, data reporting

Answer: D

Explanation:
Section: Volume A


NEW QUESTION # 124
You work as a Web developer for ABC Inc. You want to investigate the Cross-Site Scripting attack on your company's Web site. Which of the following methods of investigation can you use to accomplish the task?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Use a Web proxy to view the Web server transactions in real time and investigate any communication with outside servers.
  • B. Look at the Web server's logs and normal traffic logging.
  • C. Use Wireshark to capture traffic going to the server and then searching for the requests going to the input page, which may give log of the malicious traffic and the IP address of the source.
  • D. Review the source of any HTML-formatted e-mail messages for embedded scripts or links in the URL to the company's site.

Answer: A,B,D


NEW QUESTION # 125
Adam works as a professional Computer Hacking Forensic Investigator. He works with the local police. A project has been assigned to him to investigate an iPod, which was seized from a student of the high school. It is suspected that the explicit child pornography contents are stored in the iPod. Adam wants to investigate the iPod extensively. Which of the following operating systems will Adam use to carry out his investigations in more extensive and elaborate manner?

  • A. MINIX 3
  • B. Mac OS
  • C. Windows XP
  • D. Linux

Answer: B


NEW QUESTION # 126
Which of the following is the initiative of United States Department of Justice, which provides state and local law enforcement agencies the tools to prevent Internet crimes against children, and catches the distributors of child pornography on the Internet?

  • A. Anti-Child Porn.org (ACPO)
  • B. Project Safe Childhood (PSC)
  • C. Internet Crimes Against Children (ICAC)
  • D. Innocent Images National Initiative (IINI)

Answer: C

Explanation:
Section: Volume A


NEW QUESTION # 127
You work as a Network Administrator for Perfect Solutions Inc. You install Windows 98 on a computer. By default, which of the following folders does Windows 98 setup use to keep the registry tools?

  • A. $SYSTEMROOT$WINDOWSSYSTEM32
  • B. $SYSTEMROOT$WINDOWSREGISTRY
  • C. $SYSTEMROOT$REGISTRY
  • D. $SYSTEMROOT$WINDOWS

Answer: D

Explanation:
Section: Volume A


NEW QUESTION # 128
Adam works as a professional Computer Hacking Forensic Investigator with the local police of his area. A project has been assigned to him to investigate a PDA seized from a local drug dealer. It is expected that many valuable and important information are stored in this PDA. Adam follows investigative methods, which are required to perform in a pre-defined sequential manner for the successful forensic investigation of the PDA. Which of the following is the correct order to perform forensic investigation of PDA?

  • A. Examination, Identification, Collection, Documentation
  • B. Examination, Collection, Identification, Documentation
  • C. Documentation, Examination, Identification, Collection
  • D. Identification, Collection, Examination, Documentation

Answer: A


NEW QUESTION # 129
Which of the following are known as the three laws of OPSEC?
Each correct answer represents a part of the solution. Choose three.

  • A. If you don't know what to protect, how do you know you are protecting it?
  • B. If you are not protecting it (the critical and sensitive information), the adversary wins!
  • C. If you don't know about your security resources you cannot protect your network.
  • D. If you don't know the threat, how do you know what to protect?

Answer: A,B,D


NEW QUESTION # 130
Which of the following type of file systems is not supported by Linux kernel?

  • A. NTFS
  • B. HFS
  • C. vFAT
  • D. FAT32

Answer: D


NEW QUESTION # 131
You are working with a team that will be bringing in new computers to a sales department at a company. The sales team would like to keep not only their old files, but system settings as well on the new PC's. What should you do?

  • A. Copy the files and the Windows Registry to a removable media then copy it onto the new machines.
  • B. Use the User State Migration tool to move the system settings and files to the new machines.
  • C. Do a system backup (complete) on each old machine, then restore it onto the new machines
  • D. Use the Disk Management tool to move everything to the new computer.

Answer: B


NEW QUESTION # 132
Which of the following evidences are the collection of facts that, when considered together, can be used to infer a conclusion about the malicious activity/person?

  • A. Corroborating
  • B. Circumstantial
  • C. Incontrovertible
  • D. Direct

Answer: B


NEW QUESTION # 133
Which of the following file systems provides file-level security?

  • A. FAT32
  • B. NTFS
  • C. FAT
  • D. CDFS

Answer: B

Explanation:
Section: Volume A


NEW QUESTION # 134
John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. He copies the whole structure of the We-are-secure Web site to the local disk and obtains all the files on the Web site. Which of the following techniques is he using to accomplish his task?

  • A. Web ripping
  • B. Eavesdropping
  • C. Fingerprinting
  • D. TCP FTP proxy scanning

Answer: A


NEW QUESTION # 135
You work as a Network Administrator for NetTech Inc. To ensure the security of files, you encrypt data files using Encrypting File System (EFS). You want to make a backup copy of the files and maintain security settings. You can backup the files either to a network share or a floppy disk. What will you do to accomplish this?

  • A. Copy the files to a network share on an NTFS volume.
  • B. Place the files in an encrypted folder. Then, copy the folder to a floppy disk.
  • C. Copy the files to a floppy disk that has been formatted using Windows 2000 Professional.
  • D. Copy the files to a network share on a FAT32 volume.

Answer: A

Explanation:
Section: Volume C
Explanation/Reference:


NEW QUESTION # 136
......


GIAC GCFA Exam Syllabus Topics:

TopicDetails
Topic 1
  • Identify artifacts such as malicious processes, suspicious drivers and malware techniques such as code injection and rootkits
  • Identify and document indicators of compromise on a systems
Topic 2
  • Demonstrate an understanding of the methodology required to collect and process timeline data from a Windows systems
  • Identification of Normal System and User Activity
Topic 3
  • Demonstrate an understanding of the Windows filesystem time structure
  • Demonstrate an understanding of the techniques required to identify, document
Topic 4
  • Demonstrate an understanding of Windows system artifacts and how to collect and analyze data
  • Demonstrate an understanding of how and when to collect volatile data from a system

 

GIAC Exam Practice Test To Gain Brilliante Result: https://www.itexamsimulator.com/GCFA-brain-dumps.html

Tested Material Used To GCFA: https://drive.google.com/open?id=1xuubnrCm46UVp_lpgmubxkooOp4COPlk