GIAC Forensics Examiner Practice Test GCFE Prüfungsfragen mit Lösungen:
1. How do SMTP headers contribute to email forensic analysis? (Choose Two)
A) They contain timestamps and routing information of email transmission.
B) They provide information about the sender's and receiver's email servers.
C) They track changes to email content after sending.
D) They log user interactions within the email service.
2. During a forensic investigation, which cloud storage artifact is most useful for identifying a file's origin and version history?
A) Sync logs
B) Prefetch files
C) Application error logs
D) Version history files
3. How do 'Cache files' serve forensic investigations in browsers?
A) They offer a snapshot of all active web sessions.
B) They help reconstruct a user's browsing history through stored web content.
C) They monitor changes in system hardware.
D) They list all user-generated error reports.
4. How can the analysis of 'USB device connection logs' aid in a forensic investigation?
A) They track user interactions with software applications.
B) They provide data on internet browsing history.
C) They log changes in screen resolution settings.
D) They can reveal the history of external devices connected to the system, potentially identifying unauthorized data transfers or breaches.
5. How can an analyst use 'DNS logs' from Windows event logs to track malicious activity?
A) By monitoring changes to network configurations.
B) By identifying unusual patterns of DNS queries, which may suggest phishing or malware communication.
C) By tracking the frequency of application updates.
D) By listing all connected USB devices.
Fragen und Antworten:
| 1. Frage Antwort: A,B | 2. Frage Antwort: D | 3. Frage Antwort: B | 4. Frage Antwort: D | 5. Frage Antwort: B |






961 Kundenbewertungen

