최신GIAC Forensics Examiner Practice Test - GCFE무료샘플문제
문제1
What type of artifacts are commonly recovered from the synchronization folders of cloud storage applications like Dropbox and Google Drive?
What type of artifacts are commonly recovered from the synchronization folders of cloud storage applications like Dropbox and Google Drive?
정답: D
문제2
When examining browser artifacts, which of the following files are crucial for reconstructing a user's search history? (Choose Two)
When examining browser artifacts, which of the following files are crucial for reconstructing a user's search history? (Choose Two)
정답: A,D
문제3
Which Windows file contains user-specific settings and configuration data, making it crucial for forensic analysis?
Which Windows file contains user-specific settings and configuration data, making it crucial for forensic analysis?
정답: A
문제4
An examiner wants to identify persistence via Run keys. Which Registry location should they check?
An examiner wants to identify persistence via Run keys. Which Registry location should they check?
정답: C
문제5
What can be inferred from the analysis of 'logon events' recorded in Windows systems? (Choose Two)
What can be inferred from the analysis of 'logon events' recorded in Windows systems? (Choose Two)
정답: B,D
문제6
In digital forensics, why is 'triage analysis' important?
In digital forensics, why is 'triage analysis' important?
정답: D
문제7
Which of the following artifacts are valuable for tracking user access to a web-based email service? (Choose Two)
Which of the following artifacts are valuable for tracking user access to a web-based email service? (Choose Two)
정답: C,D
문제8
In Windows, which artifact provides a history of files and folders recently accessed by a user?
In Windows, which artifact provides a history of files and folders recently accessed by a user?
정답: C
문제9
Which artifacts are essential for identifying URLs that were typed manually by a user during a browsing session? (Choose Two)
Which artifacts are essential for identifying URLs that were typed manually by a user during a browsing session? (Choose Two)
정답: B,D
문제10
Why is it important for forensic analysts to understand the concept of 'file carving' in the recovery of digital evidence?
Why is it important for forensic analysts to understand the concept of 'file carving' in the recovery of digital evidence?
정답: D
문제11
What fundamental principle of digital forensics involves ensuring that the evidence remains unaltered from the time of collection to presentation in court?
What fundamental principle of digital forensics involves ensuring that the evidence remains unaltered from the time of collection to presentation in court?
정답: B