The GIAC Certified Forensics Analyst (GCFA) is a highly respected certification that is recognized globally. The certification is designed for professionals who work in digital forensics, including law enforcement officers, private investigators, and information security professionals. The GCFA exam is challenging and covers a wide range of topics, but passing it enables candidates to demonstrate their knowledge and skills in forensic analysis techniques, investigative procedures, and the use of forensic tools and software. GCFA certification holders are in high demand in the digital forensics industry and are eligible for a variety of job roles.

GIAC Certified Forensics Analyst Sample Questions (Q128-Q133):

You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to allow direct access to the filesystems data structure. Which of the following Unix commands can you use to accomplish the task?

  • A. df
  • B. dosfsck
  • C. debugfs
  • D. du

Answer: C

By gaining full control of router, hackers often acquire full control of the network. Which of the following methods are commonly used to attack Routers?
Each correct answer represents a complete solution. Choose all that apply.

  • A. By launching Max Age attack
  • B. By launching Social Engineering attack
  • C. Route table poisoning
  • D. By launching Sequence++ attack

Answer: A,C,D

Which of the following standard technologies is not used to interface hard disk with the computer?

  • A. USB
  • B. SCSI
  • C. PS/2
  • D. IDE/ATA

Answer: C

John works as a professional Ethical Hacker. He has been assigned the project of testing the security of He enters the following command on the Linux terminal:
chmod -rwSr—– secure.c
Considering the above scenario, which of the following statements is true?

  • A. The Sticky bit is set, but other users have no execute permission.
  • B. The SGID bit is set, but the group execute permission is not set.
  • C. The Sticky bit is set and other users have the execute permission.
  • D. The SUID bit is set, but the owner has no execute permission.

Answer: D

Mark is taking a data backup during non-working hours from a remote computer on the network by using the Backup utility. What will he do to ensure that the backup has no errors?

  • A. Verify the backup.
  • B. Take a full backup.
  • C. Log off all the users from the network.
  • D. Take an incremental backup.

Answer: A


