GIAC GCFE Prüfungsthemen:
| Abschnitt | Gewichtung | Ziele |
|---|---|---|
| Thema 1: Auswertung und Berichterstellung | 15% | - Standards für die Erstellung forensischer Berichte - Auswertung und Verknüpfung von Beweismitteln - Erstellung und Auswertung von Zeitablaufdiagrammen |
| Thema 2: Forensik von Anwendungen und Kommunikationsdaten | 20% | - E-Mail-Forensik (lokal, webbasiert, M365) - Spuren von Cloud-Speicherdiensten und deren Auswertung - Browserbezogene Spuren und deren Auswertung |
| Thema 3: Grundlagen der digitalen Forensik | 15% | - Aufbau von Windows-Dateisystemen - Forensische Methodik und zentrale Konzepte - Aufbau und Analyse der Windows-Registrierungsdatenbank |
| Thema 4: Beweissicherung und Vor-Ort-Analyse | 15% | - Techniken der Vor-Ort-Analyse - Datenerhaltung und Integritätssicherung - Verfahren zur Erhebung forensischer Beweise |
| Thema 5: Analyse von Windows-Systemen und Spuren | 20% | - Spuren von Dateien und Programmausführungen - Spuren von Benutzerkonten und Nutzeraktivitäten - Analyse von USB- und Wechseldatenträgern - Systembezogene Spuren und Konfigurationsdaten |
| Thema 6: Protokoll- und Ereignisanalyse | 15% | - Auswertung und forensische Aussagekraft von Protokollen - Arten und Zweck von Windows-Ereignisprotokollen - Analyse von Dienst- und Anwendungsprotokollen |
GIAC Forensics Examiner Practice Test GCFE Prüfungsfragen mit Lösungen
How do SMTP headers contribute to email forensic analysis? (Choose Two)
- A. They contain timestamps and routing information of email transmission.
- B. They provide information about the sender's and receiver's email servers.
- C. They track changes to email content after sending.
- D. They log user interactions within the email service.
During a forensic investigation, which cloud storage artifact is most useful for identifying a file's origin and version history?
- A. Sync logs
- B. Prefetch files
- C. Application error logs
- D. Version history files
How do 'Cache files' serve forensic investigations in browsers?
- A. They offer a snapshot of all active web sessions.
- B. They help reconstruct a user's browsing history through stored web content.
- C. They monitor changes in system hardware.
- D. They list all user-generated error reports.
How can the analysis of 'USB device connection logs' aid in a forensic investigation?
- A. They track user interactions with software applications.
- B. They provide data on internet browsing history.
- C. They log changes in screen resolution settings.
- D. They can reveal the history of external devices connected to the system, potentially identifying unauthorized data transfers or breaches.
How can an analyst use 'DNS logs' from Windows event logs to track malicious activity?
- A. By monitoring changes to network configurations.
- B. By identifying unusual patterns of DNS queries, which may suggest phishing or malware communication.
- C. By tracking the frequency of application updates.
- D. By listing all connected USB devices.






1051 Kundenbewertungen

