Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the GIAC Forensics GCFA Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam GCFA Premium Access

View all detail and faqs for the GCFA exam


734 Students Passed

85% Average Score

93% Same Questions
Viewing page 4 out of 10 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which of the following is the correct order of digital investigations Standard Operating Procedure (SOP)?

Options:

A.

Initial analysis, request for service, data collection, data analysis, data reporting

B.

Initial analysis, request for service, data collection, data reporting, data analysis

C.

Request for service, initial analysis, data collection, data reporting, data analysis

D.

Request for service, initial analysis, data collection, data analysis, data reporting

Questions # 32:

Which of the following is the correct order of loading system files into the main memory of the system, when the computer is running on Microsoft's Windows XP operating system?

Options:

A.

NTLDR, BOOT.ini, HAL.dll, NTDETECT.com, NTOSKRNL.exe

B.

NTLDR, BOOT.ini, NTDETECT.com, HAL.dll, NTOSKRNL.exe

C.

NTLDR, BOOT.ini, HAL.dll, NTDETECT.com, NTOSKRNL.exe

D.

BOOT.ini, HAL.dll, NTDETECT.com, NTLDR, NTOSKRNL.exe

Questions # 33:

Which of the following articles defines illegal access to the computer or network in Chapter 2 of Section 1, i.e., Substantive criminal law of the Convention on Cybercrime passed by the Council of Europe?

Options:

A.

Article 2

B.

Article 5

C.

Article 16

D.

Article 3

Questions # 34:

You work as a Network Administrator for Perfect Solutions Inc. The company has a Linux-based network. You are working as a root user on the Linux operating system. While performing some security investigation, you want to see the hostname and IP address from where users logged in.

Which of the following commands will you use to accomplish the task?

Options:

A.

Dig

B.

Netstat

C.

Nslookup

D.

Last

Questions # 35:

Which of the following steps are generally followed in computer forensic examinations?

Each correct answer represents a complete solution. Choose three.

Options:

A.

Encrypt

B.

Acquire

C.

Authenticate

D.

Analyze

Questions # 36:

Which of the following registry hives stores information about the file extensions that are mapped to their corresponding applications?

Options:

A.

HKEY_CURRENT_USER

B.

HKEY_USERS

C.

HKEY_CLASSES_ROOT

D.

HKEY_LOCAL_MACHINE

Questions # 37:

Which of the following types of virus makes changes to a file system of a disk?

Options:

A.

Master boot record virus

B.

Stealth virus

C.

Cluster virus

D.

Macro virus

Questions # 38:

John works as a Network Security Professional. He is assigned a project to test the security of www.we-are-secure.com. He is working on the Linux operating system and wants to install an Intrusion Detection System on the We-are-secure server so that he can receive alerts about any hacking attempts. Which of the following tools can John use to accomplish the task?

Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

SARA

B.

Snort

C.

Tripwire

D.

Samhain

Questions # 39:

Which of the following is used to back up forensic evidences or data folders from the network or locally attached hard disk drives?

Options:

A.

WinHex

B.

Device Seizure

C.

FAR system

D.

Vedit

Questions # 40:

You want to change the attribute of a file named ACE.TXT to Hidden. Which command line will enable you to set the attribute?

Options:

A.

ATTRIB ACE.TXT -H

B.

ATTRIB ACE.TXT /HR

C.

ATTRIB ACE.TXT +H

D.

ATTRIB ACE.TXT /H

Viewing page 4 out of 10 pages
Viewing questions 31-40 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.