GIAC GCFA - GIACCertified Forensics Analyst Exam

Question #11 (Topic: Topic 1)
Which of the following evidences are the collection of facts that, when considered together,
can be used to infer a conclusion about the malicious activity/person?
A. Corroborating B. Circumstantial C. Incontrovertible D. Direct
Answer: B
Question #12 (Topic: Topic 1)
Mark works as a security manager for SofTech Inc. He is using a technique for monitoring
what the employees are doing with corporate resources. Which of the following techniques
is being used by Mark to gather evidence of an ongoing computer crime if a member of the
staff is e-mailing company's secrets to an opponent?
A. Electronic surveillance B. Civil investigation C. Physical surveillance D. Criminal investigation
Answer: A
Question #13 (Topic: Topic 1)
Peter works as a Technical Representative in a CSIRT for SecureEnet Inc. His team is
called to investigate the computer of an employee, who is suspected for classified data
theft. Suspect's computer runs on Windows operating system. Peter wants to collect data
and evidences for further analysis. He knows that in Windows operating system, the data is
searched in pre-defined steps for proper and efficient analysis. Which of the following is the
correct order for searching data on a Windows based system?
A. Volatile data, file slack, registry, memory dumps, file system, system state backup, internet traces B. Volatile data, file slack, registry, system state backup, internet traces, file system, memory dumps C. Volatile data, file slack, internet traces, registry, memory dumps, system state backup, file system D. Volatile data, file slack, file system, registry, memory dumps, system state backup, internet traces
Answer: D
Question #14 (Topic: Topic 1)
Peter works as a Computer Hacking Forensic Investigator. He has been called by an
organization to conduct a seminar to give necessary information related to sexual
harassment within the work place. Peter started with the definition and types of sexual
harassment. He then wants to convey that it is important that records of the sexual
harassment incidents should be maintained, which helps in further legal prosecution. Which
of the following data should be recorded in this documentation?
Each correct answer represents a complete solution. Choose all that apply.
A. Names of the victims B. Date and time of incident C. Nature of harassment D. Location of each incident
Answer: A,B,D
Question #15 (Topic: Topic 1)
Which of the following is a type of intruder detection that involves logging network events to
a file for an administrator to review later?
A. Packet detection B. Passive detection C. Active detection D. Event detection
Answer: B
Download Exam
Page: 3 / 64
Total 318 questions