GCFA Exam Questions
314 real GCFA exam questions with expert-verified answers and explanations. Page 2 of 7.
- Question #53Advanced Mac & Linux Forensics
Mark works as a Network Administrator for Net Perfect Inc. The company has a Linux-based network. Mark installs a Checkpoint Firewall NGX on a SecurePlatform device. He performs a...
firewall backupSecurePlatformCheckpoint NGXLinux network - Question #54Advanced Incident Response & Digital Forensics Fundamentals
Which of the following evidences are the collection of facts that, when considered together, can be used to infer a conclusion about the malicious activity/person?
circumstantial evidenceevidence typesdigital forensicsforensic investigation - Question #56Advanced Windows Artifacts & Browser Forensics
You are working with a team that will be bringing in new computers to a sales department at a company. The sales team would like to keep not only their old files, but system settin...
USMTsystem migrationWindows Registryfile migration - Question #57Advanced Incident Response & Digital Forensics Fundamentals
By gaining full control of router, hackers often acquire full control of the network. Which of the following methods are commonly used to attack Routers? Each correct answer repres...
router attacksroute table poisoningMax Age attacknetwork exploitation - Question #58File System & Registry Forensics
Which of the following is the process of comparing cryptographic hash functions of system executables and configuration files?
file integrity auditingcryptographic hashhash comparisonsystem integrity - Question #59Advanced Incident Response & Digital Forensics Fundamentals
Which of the following are the primary goals of the incident handling team? Each correct answer represents a complete solution. Choose all that apply.
incident handlingincident responsedamage preventionincident goals - Question #60Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is the correct order of digital investigations Standard Operating Procedure(SOP)?
digital investigation SOPforensic procedureinvestigation workflowincident response process - Question #61Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is the initiative of United States Department of Justice, which provides state and local law enforcement agencies the tools to prevent Internet crimes agains...
ICACInternet crimes against childrenlaw enforcementlegal frameworks - Question #62Advanced Mac & Linux Forensics
Mark is the Administrator of a Linux computer. He wants to check the status of failed Telnet-based login attempts on the Linux computer. Which of the following shell commands will...
GREP commandLinux logslogin monitoringTelnet security - Question #63Threat Hunting & Timeline Analysis
Which of the following tools are used for footprinting? Each correct answer represents a complete solution. Choose all that apply.
footprintingWhoisTraceroutereconnaissance tools - Question #64File System & Registry Forensics
You work as a Network Administrator for Peach Tree Inc. The company currently has a FAT-based Windows NT network. All client computers run Windows 98. The management wants all clie...
FAT to NTFS conversionCONVERT utilitydual-bootfile system security - Question #65Advanced Mac & Linux Forensics
You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to allow direct access to the filesystems data structure. Which of the followin...
debugfsUnix filesystemfilesystem data structureLinux commands - Question #66Advanced Incident Response & Digital Forensics Fundamentals
You work as a Network Administrator for Web World Inc. You want to host an e-commerce Web site on your network. You want to ensure that storage of credit card information is secure...
credit card securityencryptionaccess controldata protection - Question #67Advanced Incident Response & Digital Forensics Fundamentals
You work as a Network Security Analyzer. You got a suspicious email while working on a forensic project. Now, you want to know the IP address of the sender so that you can analyze...
email forensicsemail header analysisIP address tracingemail investigation - Question #68File System & Registry Forensics
You work as a Network Administrator for uCertify Inc. You want to edit the MSDOS.SYS file, in your computer, from the DOS prompt. You are unable to find the file. What is the most...
MSDOS.SYShidden filesDOS system filesWindows artifacts - Question #69Advanced Incident Response & Digital Forensics Fundamentals
John works for an Internet Service Provider (ISP) in the United States. He discovered child pornography material on a Web site hosted by the ISP. John immediately informed law enfo...
Sexual Predators Actchild pornographyISP legal obligationslegal reporting requirements - Question #70Advanced Incident Response & Digital Forensics Fundamentals
Adam works as a professional Computer Hacking Forensic Investigator with the local police of his area. A project has been assigned to him to investigate a PDA seized from a local d...
PDA forensicsinvestigation methodologyforensic process orderevidence collection - Question #71Advanced Incident Response & Digital Forensics Fundamentals
The incident response team has turned the evidence over to the forensic team. Now, it is the time to begin looking for the ways to improve the incident response process for next ti...
incident responsepost-incident reviewIR process improvementlessons learned - Question #72File System & Registry Forensics
Adam works as a professional Computer Hacking Forensic Investigator. He has been assigned with the project of investigating an iPod, which is suspected to contain some explicit mat...
write blockerStorageDevicePoliciesregistry keysevidence preservation - Question #74Threat Hunting & Timeline Analysis
Nathan works as a Computer Hacking Forensic Investigator for SecureEnet Inc. He uses Visual TimeAnalyzer software to track all computer usage by logging into individual users accou...
timeline analysisVisual TimeAnalyzeruser activity monitoringforensic tools - Question #75Advanced Incident Response & Digital Forensics Fundamentals
Which of the following IP addresses are private addresses? Each correct answer represents a complete solution. Choose all that apply.
private IP addressesRFC 1918IPv4network addressing - Question #76File System & Registry Forensics
Sandra, a novice computer user, works on Windows environment. She experiences some problem regarding bad sectors formed in a hard disk of her computer. She wants to run CHKDSK comm...
CHKDSKbad sectorsdisk repairWindows commands - Question #77File System & Registry Forensics
Which of the following statements about an extended partition are true? Each correct answer represents a complete solution. Choose two.
extended partitiondisk partitioninglogical drivesMBR structure - Question #78Advanced Incident Response & Digital Forensics Fundamentals
You are reviewing a Service Level Agreement between your company and a Web development vendor. Which of the following are security requirements you should look for in this SLA? Eac...
SLAvendor security requirementsencryption standardssecurity monitoring - Question #79Advanced Mac & Linux Forensics
Which of the following is used to detect the bad sectors in a hard disk under Linux environment?
badblocksbad sector detectionLinux disk toolsdisk forensics - Question #80File System & Registry Forensics
Which of the following statements are NOT true about volume boot record or Master Boot Record? Each correct answer represents a complete solution. Choose all that apply.
MBRvolume boot recordboot sector structuredisk layout - Question #81Memory Forensics & Anti-Forensics Detection
Which of the following tools can be used by a user to hide his identity? Each correct answer represents a complete solution. Choose all that apply.
anonymizerproxy serveridentity concealmentanti-forensics - Question #82Memory Forensics & Anti-Forensics Detection
Normally, RAM is used for temporary storage of data. But sometimes RAM data is stored in the hard disk, what is this method called?
virtual memoryRAMpage filememory management - Question #84Advanced Incident Response & Digital Forensics Fundamentals
Nathan works as a professional Ethical Hacker. He wants to see all open TCP/IP and UDP ports of his computer. Nathan uses the netstat command for this purpose but he is still unabl...
fportnetstatopen portsprocess-to-port mapping - Question #85Advanced Mac & Linux Forensics
Adam works as a professional Computer Hacking Forensic Investigator. He works with the local police. A project has been assigned to him to investigate an iPod, which was seized fro...
iPod forensicsMac OSApple device forensicsmobile investigation - Question #86File System & Registry Forensics
Which of the following parameters is NOT used for calculating the capacity of the hard disk?
hard disk capacitydisk geometryplattersdisk structure - Question #87Advanced Incident Response & Digital Forensics Fundamentals
In which of the following access control models can a user not grant permissions to other users to see a copy of an object marked as secret that he has received, unless they have t...
mandatory access controlMAC modelaccess control modelssecurity labels - Question #88Advanced Incident Response & Digital Forensics Fundamentals
Adam works as a professional Computer Hacking Forensic Investigator. He has been called by the FBI to examine data of the hard disk, which is seized from the house of a suspected t...
forensic imagingImageMASSterdisk acquisitionhash verification - Question #89Advanced Incident Response & Digital Forensics Fundamentals
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate the BlackBerry, which is suspected to be used to hide some im...
BlackBerry forensicsmobile device forensicsevidence preservationpush data isolation - Question #90Advanced Incident Response & Digital Forensics Fundamentals
Which of the following prevents malicious programs from attacking a system?
malware preventionanti-virusendpoint security - Question #91Advanced Incident Response & Digital Forensics Fundamentals
Which of the following terms refers to a mechanism which proves that the sender really sent a particular message?
non-repudiationdigital signaturesauthenticationsecurity principles - Question #92Memory Forensics & Anti-Forensics Detection
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him by the chief security officer of a cloth manufacturing company who suspects...
mobile forensicsiPhoneanti-forensicsdevice boot - Question #93Advanced Windows Artifacts & Browser Forensics
Which of the following is a file management tool?
Windows Explorerfile managementWindows tools - Question #94Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is a correct sequence of different layers of Open System Interconnection (OSI) model?
OSI modelnetwork layersnetworking fundamentals - Question #95Threat Hunting & Timeline Analysis
John works as a professional Ethical Hacker. He is assigned a project to test the security of we-are- secure network and intercept a conversation between two employees of the compa...
session hijackingnetwork forensicsattack toolsHunt - Question #96Advanced Incident Response & Digital Forensics Fundamentals
You are the Network Administrator and your company has recently implemented encryption for all emails. You want to check to make sure that the email packages are being encrypted. W...
packet sniffingemail encryptionnetwork monitoringtraffic analysis - Question #97Advanced Mac & Linux Forensics
Which of the following file systems contains hardware settings of a Linux computer?
Linux filesystemproc filesystemhardware settingssystem configuration - Question #98Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is a set of exclusive rights granted by a state to an inventor or his assignee for a fixed period of time in exchange for the disclosure of an invention?
patentintellectual propertylegal concepts - Question #99Advanced Incident Response & Digital Forensics Fundamentals
Which of the following tools can be used to perform a whois query? Each correct answer represents a complete solution. Choose all that apply.
whoisOSINT toolsreconnaissancenetwork enumeration - Question #100Advanced Mac & Linux Forensics
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate the main server of SecureEnet Inc. The server runs on Debian...
GRUBLinux boot loaderDebian forensicsboot configuration - Question #101Advanced Incident Response & Digital Forensics Fundamentals
You are the Security Consultant and have been contacted by a client regarding their encryption and hashing algorithms. Their in-house network administrator tells you that their cur...
MD5hash collisioncryptographic weaknesseshashing algorithms - Question #102Advanced Incident Response & Digital Forensics Fundamentals
You work as a Network Administrator for a bank. For securing the bank's network, you configure a firewall and an IDS. In spite of these security measures, intruders are able to att...
IDSfalse negativeintrusion detectionalert tuning - Question #103Advanced Mac & Linux Forensics
John works as a Network Administrator for Perfect Solutions Inc. The company has a Linux-based network. John is working as a root user on the Linux operating system. Which of the f...
df commandmounted filesystemsLinux commandsdisk usage - Question #104File System & Registry Forensics
Which of the following statements about registry is true? Each correct answer represents a complete solution. Choose three.
Windows Registryregistry hivesregistry structureWindows configuration - Question #105Advanced Incident Response & Digital Forensics Fundamentals
Which of the following diagnostic codes sent by POST to the internal port h80 refers to the system board error?
POST codeshardware diagnosticssystem boardBIOS