
JPNTest GCFE問題集でリアル試験問題でテストエンジン問題集でトレーニング
GIAC GCFEテスト問題集とオンライン試験エンジン
質問 # 61
In digital forensics, why is 'triage analysis' important?
Response:
- A. It monitors the effectiveness of antivirus software.
- B. It provides detailed logs of system errors and crashes.
- C. It allows for a quick preliminary assessment to determine the relevance of data before undergoing a full forensic analysis.
- D. It tracks changes in network configurations.
正解:C
質問 # 62
In Windows, which artifact provides a history of files and folders recently accessed by a user?
Response:
- A. Application error logs
- B. Prefetch files
- C. RecentDocs registry key
- D. Event logs
正解:C
質問 # 63
Why is it important to analyze the 'Outbox' and 'Drafts' folders in an email forensic investigation?
Response:
- A. They provide data on files downloaded from emails.
- B. They detail the user's changes to email display settings.
- C. They can show emails that were intended to be sent but were not successfully transmitted.
- D. They list the security updates applied to the email client.
正解:C
質問 # 64
What forensic value does the 'Web Data' file in Chrome offer?
Response:
- A. It lists all installed browser extensions.
- B. It includes details on saved passwords and autofill information.
- C. It tracks changes to browser security settings.
- D. It provides data on external devices connected to the system.
正解:B
質問 # 65
In browser structure analysis, what is the significance of analyzing 'Local Storage' files in modern web browsers?
Response:
- A. They provide insights into user-specific data stored by websites.
- B. They log user-installed applications and usage.
- C. They detail the browser's network security configurations.
- D. They show changes to browser security levels.
正解:A
質問 # 66
Which browser artifacts are essential for identifying cookies and tracking user login sessions?
(Choose two)
Response:
- A. HTML5 Local Storage
- B. Cookies.sqlite
- C. Windows Event Logs
- D. Cache files
- E. Network error logs
正解:A、B
質問 # 67
Which of the following is most useful for identifying manually typed URLs in a browser forensic investigation?
Response:
- A. Form history
- B. Firewall logs
- C. Index.dat
- D. Session restore files
正解:A
質問 # 68
What type of forensic information can be gleaned from analyzing 'user profile' data on a Windows system?
Response:
- A. It tracks the installation of system updates.
- B. It can reveal user preferences, installed applications, and login history, providing a comprehensive view of user activity.
- C. It logs network security settings.
- D. It monitors changes in hardware configurations.
正解:B
質問 # 69
Why is live data acquisition important in some forensic investigations?
Response:
- A. It logs hardware changes
- B. It speeds up the forensic imaging process
- C. It captures volatile data like RAM contents, which can be lost on shutdown
- D. It helps recover data after a system crash
正解:C
質問 # 70
In email forensic analysis, what role do SMTP headers play?
Response:
- A. They contain the content of the email body.
- B. They include the encryption method used for the email.
- C. They log the transfer route and timestamps of the email.
- D. They store the list of attached files.
正解:C
質問 # 71
How do SMTP headers contribute to email forensic analysis?
(Choose Two)
Response:
- A. They provide information about the sender's and receiver's email servers.
- B. They track changes to email content after sending.
- C. They log user interactions within the email service.
- D. They contain timestamps and routing information of email transmission.
正解:A、D
質問 # 72
A forensic investigator is analyzing a Windows system suspected of containing malware. The user claims they did not install any suspicious programs. Which artifacts would you analyze to confirm or refute this claim?
(Select three)
Response:
- A. Application error logs
- B. Prefetch files
- C. Master File Table (MFT)
- D. Recycle Bin contents
- E. System log
正解:A、B、C
質問 # 73
Which Windows artifact is primarily used to store metadata about files, including the file creation and modification times?
Response:
- A. Index.dat
- B. Master File Table (MFT)
- C. Registry keys
- D. Event logs
正解:B
質問 # 74
How does the examination of 'script files' used in system automation contribute to forensic analysis?
Response:
- A. It provides a history of network security settings.
- B. It details the frequency of user logouts and shutdowns.
- C. It logs user activity in real-time.
- D. It shows the scripts used for automating system tasks, which can include malicious activities or unauthorized changes.
正解:D
質問 # 75
Which of the following browser artifacts can help identify the websites visited by a user?
Response:
- A. Security certificates
- B. Network configuration files
- C. Firewall settings
- D. Places.sqlite
正解:D
質問 # 76
What role do 'desktop search databases' play in user artifact analysis?
(Choose Two)
Response:
- A. They help identify the usage of encrypted communications.
- B. They provide metadata about accessed documents and media files.
- C. They store indexed data about files and emails, making it possible to reconstruct user search activities and interests.
- D. They log user preferences for network settings.
正解:B、C
質問 # 77
Which of the following are common methods used to preserve the integrity of digital evidence?
(Choose two)
Response:
- A. System reboot
- B. Write blockers
- C. Defragmentation
- D. Chain of custody documentation
正解:B、D
質問 # 78
What is the purpose of using 'timeline analysis' in forensic investigations?
Response:
- A. It provides a continuous log of system uptime and downtime.
- B. It tracks the frequency of password changes.
- C. It helps in establishing a chronological order of events based on the creation, modification, and access times of files and other digital artifacts.
- D. It details changes in system security settings.
正解:C
質問 # 79
......
GIAC GCFE問題を提供していますGIAC Information Security問題集と完璧な解答付き:https://www.jpntest.com/shiken/GCFE-mondaishu
信頼され続けるGCFE試験のコツとPDF試験材料:https://drive.google.com/open?id=1pP3qHT9V0ySeBFCyJLxF_hZ8APkh6Qa-