최신GIAC iOS and macOS Examiner - GIME무료샘플문제
문제1
What information can be analyzed from the Contacts application in an Apple device?
What information can be analyzed from the Contacts application in an Apple device?
정답: A
문제2
How can one use SQL to find the specific data within a database table related to an application's functionality?
How can one use SQL to find the specific data within a database table related to an application's functionality?
정답: C
문제3
Where are Safari browser downloads typically stored on macOS?
Where are Safari browser downloads typically stored on macOS?
정답: A
문제4
How is a timeline useful in forensic analysis?
How is a timeline useful in forensic analysis?
정답: D
문제5
What can be inferred from a consistent login pattern found during a "Pattern of Life" analysis?
What can be inferred from a consistent login pattern found during a "Pattern of Life" analysis?
정답: A
문제6
Which artifacts are commonly examined during a macOS triage to determine user accounts and system information? (Select two)
Which artifacts are commonly examined during a macOS triage to determine user accounts and system information? (Select two)
정답: C,D
문제7
You are investigating a macOS device that shows signs of compromise, including abnormal network activity and unauthorized system modifications.
What steps should you take to gather evidence of the malware's presence and determine how it compromised the system? (Choose three)
You are investigating a macOS device that shows signs of compromise, including abnormal network activity and unauthorized system modifications.
What steps should you take to gather evidence of the malware's presence and determine how it compromised the system? (Choose three)
정답: A,B,C
문제8
What type of data can be found in the com.apple.TimeMachine plist file?
What type of data can be found in the com.apple.TimeMachine plist file?
정답: B
문제9
How can an investigator use Unified Logs in macOS for timeline creation?
How can an investigator use Unified Logs in macOS for timeline creation?
정답: A
문제10
How can file system operations leave behind critical evidence?
How can file system operations leave behind critical evidence?
정답: D
문제11
What distinguishes the APFS cloning feature from a standard file copy in the context of forensic analysis?
What distinguishes the APFS cloning feature from a standard file copy in the context of forensic analysis?
정답: B
문제12
What does an analysis of iCloud data NOT typically provide?
What does an analysis of iCloud data NOT typically provide?
정답: D
문제13
Which macOS tool can be used to create a forensic disk image of a target drive?
Which macOS tool can be used to create a forensic disk image of a target drive?
정답: B
문제14
How does "Pattern of Life" analysis benefit digital forensic investigations?
How does "Pattern of Life" analysis benefit digital forensic investigations?
정답: B
문제15
In analyzing iCloud data, what is a key factor in distinguishing between different document versions?
In analyzing iCloud data, what is a key factor in distinguishing between different document versions?
정답: D