Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the GIAC Forensics GCFA Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam GCFA Premium Access

View all detail and faqs for the GCFA exam


734 Students Passed

85% Average Score

93% Same Questions
Viewing page 9 out of 10 pages
Viewing questions 81-90 out of questions
Questions # 81:

Which of the following tools is a wireless sniffer and analyzer that works on the Windows operating system?

Options:

A.

Kismet

B.

Airsnort

C.

Void11

D.

Aeropeek

Questions # 82:

John used to work as a Network Administrator for We-are-secure Inc. Now he has resigned from the company for personal reasons. He wants to send out some secret information of the company. To do so, he takes an image file and simply uses a tool image hide and embeds the secret file within an image file of the famous actress, Jennifer Lopez, and sends it to his Yahoo mail id. Since he is using the image file to send the data, the mail server of his company is unable to filter this mail. Which of the following techniques is he performing to accomplish his task?

Options:

A.

Email spoofing

B.

Social engineering

C.

Steganography

D.

Web ripping

Questions # 83:

You are the Security Consultant and have been contacted by a client regarding their encryption and hashing algorithms. Their in-house network administrator tells you that their current hashing algorithm is an older one with known weaknesses and is not collision resistant. Which algorithm are they most likely using for hashing?

Options:

A.

SHA

B.

MD5

C.

PKI

D.

Kerberos

Questions # 84:

Which of the following statements best describes the consequences of the disaster recovery plan test?

Options:

A.

If no deficiencies were found during the test, then the plan is probably perfect.

B.

The results of the test should be kept secret.

C.

The plan should not be changed no matter what the results of the test would be.

D.

If no deficiencies were found during the test, then the test was probably flawed.

Questions # 85:

Which of the following firewalls depends on the three-way handshake of the TCP protocol?

Options:

A.

Proxy-based firewall

B.

Stateful firewall

C.

Packet filter firewall

D.

Endian firewall

Questions # 86:

In 2001, the Council of Europe passed a convention on cybercrime. It was the first international treaty seeking to address computer crime and Internet crimes by harmonizing national laws, improving investigative techniques, and increasing cooperation among nations. On 1 March 2006, the Additional Protocol to the Convention on Cybercrime came into force. Which of the following statements clearly describes this protocol?

Options:

A.

The convention of cybercrime is only applied within Europe.

B.

It requires participating states to criminalize the dissemination of racist and xenophobic material through computer systems.

C.

The convention of cybercrime should immediately be put on hold until there is an inclusion of a new or amended article.

D.

English speaking states in Europe such as Ireland and the United Kingdom should sign the convention.

Questions # 87:

Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate and examine drive image of a compromised system, which is suspected to be used in cyber crime. Adam uses Forensic Sorter to sort the contents of hard drive in different categories. Which of the following type of image formats is NOT supported by Forensic Sorter?

Options:

A.

PFR image file

B.

iso image file

C.

RAW image file

D.

EnCase image file

Questions # 88:

Which of the following describes software technologies that improve portability, manageability, and compatibility of applications by encapsulating them from the underlying operating system on which they are executed?

Options:

A.

Group Policy

B.

System registry

C.

System control

D.

Application virtualization

Questions # 89:

Adam works as a Computer Hacking Forensic Investigator. He has been assigned a project to

investigate child pornography. As the first step, Adam found that the accused is using a Peer-to-peer application to network different computers together over the internet and sharing pornographic materials of children with others. Which of the following are Peer-to-Peer applications?

Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Gnutella

B.

Kismet

C.

Hamachi

D.

Freenet

Questions # 90:

Which of the following Windows XP system files handles memory management, I/O operations, and interrupts?

Options:

A.

Ntoskrnl.exe

B.

Win32k.sys

C.

Advapi32.dll

D.

Kernel32.dll

Viewing page 9 out of 10 pages
Viewing questions 81-90 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.