GCFA Exam Questions
314 real GCFA exam questions with expert-verified answers and explanations. Page 1 of 7.
- Question #1Section 5: Security
Adam, a malicious hacker has successfully gained unauthorized access to the Linux system of Umbrella Inc. Web server of the company runs on Apache. He has downloaded sensitive docu...
disk wipingdd commandanti-forensicsLinux shell - Question #2Section 5: Security
Adam works as a Computer Hacking Forensic Investigator for a garment company in the United States. A project has been assigned to him to investigate a case of a disloyal employee w...
trademark lawintellectual propertyforensic investigationcyber law - Question #3Section 6: Deployment
You work as a Network Administrator for Perfect Solutions Inc. You install Windows 98 on a computer. By default, which of the following folders does Windows 98 setup use to keep th...
Windows 98registry toolssystem folderOS setup - Question #4Section 5: Security
Which of the following tools can be used to perform tasks such as Windows password cracking, Windows enumeration, and VoIP session sniffing?
password crackingWindows enumerationVoIP sniffingCain tool - Question #5Section 6: Deployment
Which of the following type of file systems is not supported by Linux kernel?
Linux kernelfile system supportFAT32NTFS - Question #6Section 6: Deployment
Which of the following modules of OS X kernel (XNU) provides the primary system program interface?
OS X kernelXNUBSD subsystemsystem program interface - Question #7Section 5: Security
John works as a professional Ethical Hacker. He has been assigned the project of testing the The e-mail that John has received is an example of __________.
social engineeringchain lettersemail attacksethical hacking - Question #8Section 6: Deployment
You work as a Network Administrator for Blue Bell Inc. You want to install Windows XP Professional on your computer, which already has Windows Me installed. You want to configure y...
dual bootFAT32file system compatibilityWindows XP - Question #10Advanced Incident Response & Digital Forensics Fundamentals
Which of the following Acts enacted in United States allows the FBI to issue National Security Letters (NSLs) to Internet service providers (ISPs) ordering them to disclose records...
Electronic Communications Privacy ActNational Security LettersISP disclosurelegal authority - Question #11Threat Hunting & Timeline Analysis
TCP FIN scanning is a type of stealth scanning through which the attacker sends a FIN packet to the target port. If the port is closed, the victim assumes that this packet was sent...
TCP FIN scanstealth scanningOS fingerprintingnetwork reconnaissance - Question #12Advanced Incident Response & Digital Forensics Fundamentals
Which of the following encryption methods uses AES technology?
CCMPAES encryptionwireless securityWPA2 - Question #13Advanced Incident Response & Digital Forensics Fundamentals
Mark works as a security manager for SofTech Inc. He is using a technique for monitoring what the employees are doing with corporate resources. Which of the following techniques is...
electronic surveillancecorporate investigationemail monitoringevidence gathering - Question #14File System & Registry Forensics
Which of the following is the first computer virus that was used to infect the boot sector of storage media formatted with the DOS File Allocation Table (FAT) file system?
Brain virusboot sector virusFAT file systemmalware history - Question #15Threat Hunting & Timeline Analysis
Adam works as a Security Administrator for Umbrella Inc. He is responsible for securing all 15 servers of the company. To successfully accomplish the task, he enables the hardware...
banner grabbingfootprintingtelnet securitypenetration testing - Question #16Advanced Incident Response & Digital Forensics Fundamentals
Which of the following attacks saturates network resources and disrupts services to a specific computer?
Denial-of-Servicenetwork attackresource exhaustionDoS vs DDoS - Question #17Advanced Windows Artifacts & Browser Forensics
Peter works as a Technical Representative in a CSIRT for SecureEnet Inc. His team is called to investigate the computer of an employee, who is suspected for classified data theft....
order of volatilityWindows evidence collectionmemory dumpsforensic search order - Question #18File System & Registry Forensics
The MBR of a hard disk is a collection of boot records that contain disk information such as disk architecture, cluster size, and so on. The main work of the MBR is to locate and r...
MBR infectionboot sector virusmultipartite virusmalware types - Question #19Advanced Windows Artifacts & Browser Forensics
You work as a professional Computer Hacking Forensic Investigator for DataEnet Inc. You want to investigate e-mail information of an employee of the company. The suspected employee...
web email forensicsbrowser artifactstemporary internet filescookies - Question #20Advanced Incident Response & Digital Forensics Fundamentals
Which of the following methods is used by forensic investigators to acquire an image over the network in a secure manner?
EnCase SAFEnetwork forensic imagingremote acquisitionsecure authentication - Question #21Advanced Incident Response & Digital Forensics Fundamentals
You company suspects an employee of sending unauthorized emails to competitors. These emails are alleged to contain confidential company data. Which of the following is the most im...
chain of custodyemail server logsevidence preservationforensic integrity - Question #22Advanced Windows Artifacts & Browser Forensics
Which of the following is the correct order of loading system files into the main memory of the system, when the computer is running on Microsoft's Windows XP operating system?
Windows XP boot sequenceNTLDRNTDETECT.comsystem file loading order - Question #24File System & Registry Forensics
Which of the following file systems provides file-level security?
NTFSfile-level securityfile system permissionsFAT vs NTFS - Question #25Advanced Incident Response & Digital Forensics Fundamentals
Adam works as an Incident Handler for Umbrella Inc. He is informed by the senior authorities that the server of the marketing department has been affected by a malicious hacking at...
incident response phasescontainmentvolatile data captureCSIRT procedures - Question #26Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is the process of overwriting all addressable locations on a disk?
drive wipingdisk sanitizationdata destructionoverwriting - Question #27Advanced Incident Response & Digital Forensics Fundamentals
An executive in your company reports odd behavior on her PDA. After investigation you discover that a trusted device is actually copying data off the PDA. The executive tells you t...
BluesnarfingBluetooth attackPDA securitywireless attack vectors - Question #28Threat Hunting & Timeline Analysis
You work as a Network Administrator for Net Perfect Inc. The company has a Windows Server 2008 network environment. The network is configured as a Windows Active Directory-based si...
NIC failureloopback addressnetwork troubleshootingIPv6 diagnostics - Question #29File System & Registry Forensics
You want to upgrade a partition in your computer's hard disk drive from FAT to NTFS. Which of the following DOS commands will you use to accomplish this?
CONVERT commandFAT to NTFSfile system conversionDOS commands - Question #30Advanced Mac & Linux Forensics
A firewall is a combination of hardware and software, used to provide security to a network. It is used to protect an internal network or intranet against unauthorized access from...
IPTablesLinux firewallkernel 2.4network security - Question #31Advanced Incident Response & Digital Forensics Fundamentals
You work as a Web developer for ABC Inc. You want to investigate the Cross-Site Scripting attack on your company's Web site. Which of the following methods of investigation can you...
XSSweb server logsWiresharkincident investigation - Question #32Threat Hunting & Timeline Analysis
Adam works as a professional Penetration tester. A project has been assigned to him to employ penetration testing on the network of Umbrella Inc. He is running the test from home a...
penetration testingsecurity scannersvulnerability assessmentfirewall evasion - Question #33Advanced Incident Response & Digital Forensics Fundamentals
An organization monitors the hard disks of its employees' computers from time to time. Which policy does this pertain to?
privacy policyemployee monitoringorganizational policy - Question #34File System & Registry Forensics
You work as a Network Administrator for Net World International. You have configured the hard disk drive of your computer as shown in the image below: The computer is configured to...
NTFSFATdual-bootfile system compatibility - Question #35Advanced Incident Response & Digital Forensics Fundamentals
Peter works as a Computer Hacking Forensic Investigator. He has been called by an organization to conduct a seminar to give necessary information related to sexual harassment withi...
incident documentationlegal prosecutionevidence recordingHR forensics - Question #36Advanced Incident Response & Digital Forensics Fundamentals
Which of the following types of computers is used for attracting potential intruders?
honeypotintrusion detectionnetwork deception - Question #37Advanced Windows Artifacts & Browser Forensics
Which of the following standard file formats is used by Apple's iPod to store contact information?
vCardiPod forensicscontact datamobile artifacts - Question #38File System & Registry Forensics
Which of the following file systems cannot be used to install an operating system on the hard disk drive? Each correct answer represents a complete solution. Choose two.
CDFSLFSfile system typesOS installation - Question #39Advanced Incident Response & Digital Forensics Fundamentals
Which of the following types of evidence proves or disproves a specific act through oral testimony based on information gathered through the witness's five senses?
direct evidencetestimonyevidence typesforensic evidence - Question #40File System & Registry Forensics
Which of the following two cryptography methods are used by NTFS Encrypting File System (EFS) to encrypt the data stored on a disk on a file-by-file basis?
EFSNTFS encryptionpublic key cryptographydigital certificates - Question #41Advanced Incident Response & Digital Forensics Fundamentals
Which of the following sections of an investigative report covers the background and summary of the report including the outcome of the case and the list of allegations?
investigative reportreport structureforensic documentation - Question #42File System & Registry Forensics
Which of the following switches of the XCOPY command copies attributes while copying files?
XCOPYfile attributesWindows commandscommand switches - Question #43Advanced Mac & Linux Forensics
Which of the following directories in Linux operating system contains device files, which refers to physical devices?
Linux directory structure/devdevice files - Question #44Advanced Mac & Linux Forensics
Which of the following directories cannot be placed out of the root filesystem? Each correct answer represents a complete solution. Choose all that apply.
Linux filesystemroot filesystem/sbin/etc - Question #45File System & Registry Forensics
On which of the following locations does the Windows NT/2000 operating system contain the SAM, SAM.LOG, SECURITY.LOG, APPLICATION.LOG, and EVENT.LOG files?
SAM fileWindows registrysystem32 configsecurity logs - Question #46Advanced Windows Artifacts & Browser Forensics
You are handling technical support calls for an insurance company. A user calls you complaining that he cannot open a file, and that the file name appears in green while opening in...
EFSWindows Explorerfile encryptionfile color indicator - Question #47Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is a name, symbol, or slogan with which a product is identified?
trademarkintellectual propertylegal definitions - Question #48File System & Registry Forensics
Which of the following file systems supports the hot fixing feature?
NTFShot fixingfile system featuresFAT vs NTFS - Question #49Threat Hunting & Timeline Analysis
John works as a professional Ethical Hacker. He has been assigned a project for testing the performing attacks on the server is made easy and he can observe the flaws in the We-are...
polymorphic malwareIDS evasionsignature detectionshellcode - Question #50Advanced Mac & Linux Forensics
You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to fix partitions on a hard drive. Which of the following Unix commands can you...
fdiskdisk partitioningUnix commandsLinux administration - Question #51Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is a type of intruder detection that involves logging network events to a file for an administrator to review later?
passive detectionintrusion detectionnetwork loggingevent logging - Question #52File System & Registry Forensics
Which of the following file systems is designed by Sun Microsystems?
ZFSfile systemsSun Microsystemsstorage