GCFA Exam Questions
314 real GCFA exam questions with expert-verified answers and explanations. Page 4 of 7.
- Question #158Advanced Incident Response & Digital Forensics Fundamentals
Which of the following wireless network standards operates on the 5 GHz band and transfers data at a rate of 54 Mbps?
802.11awireless standards5 GHz bandWLAN specifications - Question #159Advanced Incident Response & Digital Forensics Fundamentals
Which of the following tools is a wireless sniffer and analyzer that works on the Windows operating system?
wireless snifferAeropeekpacket capturenetwork analysis tools - Question #160Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is a password-cracking program?
password crackingL0phtcrackcredential attack toolshash cracking - Question #161Advanced Mac & Linux Forensics
Which of the following is used for remote file access by UNIX/Linux systems?
NFSremote file accessLinux networkingUnix file sharing - Question #162File System & Registry Forensics
Which of the following file systems is used by both CD and DVD?
UDFoptical media file systemCD DVD forensicsCDFS - Question #163Advanced Incident Response & Digital Forensics Fundamentals
Which of the following firewalls depends on the three-way handshake of the TCP protocol?
stateful firewallTCP three-way handshakeconnection trackingnetwork security - Question #164Threat Hunting & Timeline Analysis
An attacker attempts to gain information about a network by specifically targeting the network resources and applications running on a computer. This method for gaining information...
enumerationnetwork reconnaissanceinformation gatheringactive scanning - Question #165Advanced Incident Response & Digital Forensics Fundamentals
Which of the following tools is an asterisk password revealer tool?
password revealerSnadBoyasterisk passwordcredential recovery tools - Question #166Memory Forensics & Anti-Forensics Detection
Which of the following uses hard disk drive space to provide extra memory for a computer?
virtual memorypagingmemory managementdisk-based memory - Question #167Advanced Windows Artifacts & Browser Forensics
Which of the following type of files is NOT deleted by Disk Cleanup program of Windows XP?
Disk CleanupWindows XP artifactsfile deletion behaviordisk management - Question #168Advanced Mac & Linux Forensics
Which of the following tools is used to restore deleted files from Linux and Mac OS X file system?
file recoverydeleted filesLinux forensicsMac forensics tools - Question #169Advanced Windows Artifacts & Browser Forensics
which of the following Windows XP system files handles memory management, I/O operations, and interrupts?
Windows system filesKernel32.dllmemory managementWindows kernel components - Question #170Advanced Incident Response & Digital Forensics Fundamentals
Which of the following protocols allows computers on different operating systems to share files and disk storage?
NFSfile sharing protocolsnetwork protocolscross-platform sharing - Question #171File System & Registry Forensics
Which of the following Windows Registry key contains the password file of the user?
Windows RegistryHKEY_LOCAL_MACHINEpassword storageregistry hives - Question #172File System & Registry Forensics
Which of the following tools is used to locate lost files and partitions to restore data from a formatted, damaged, or lost partition in Windows and Apple Macintosh computers?
partition recoverydata recovery toolslost partitionsVirtualLab - Question #173File System & Registry Forensics
Which of the following is used to store configuration settings and options on Microsoft Windows operating systems?
Windows Registryconfiguration managementsystem settingsregistry purpose - Question #174File System & Registry Forensics
Which of the following commands is used to create or delete partitions on Windows XP?
DISKPARTpartition managementWindows commandsdisk management - Question #175Advanced Incident Response & Digital Forensics Fundamentals
Which of the following tools is used to block email, Instant Message, Web site, or other media if inappropriate words such as pornography, violence etc. is used?
content filteringparental controlsweb filtering toolsiProtectYou - Question #176File System & Registry Forensics
Which of the following is described in the following statement: "It is a 512 bytes long boot sector that is the first sector of a default boot drive. It is also known as Volume Boo...
MBRboot sectordisk structureVolume Boot Sector - Question #177Advanced Incident Response & Digital Forensics Fundamentals
Which of the following statements best describes the consequences of the disaster recovery plan test?
disaster recoveryDRP testingincident response planningtest evaluation - Question #178Advanced Incident Response & Digital Forensics Fundamentals
Which of the following NIST RA process steps has the goal to identify the potential threat-sources and compile a threat statement listing the potential threat-sources that are appl...
NIST risk assessmentthreat identificationthreat sourcesRA process steps - Question #179Advanced Mac & Linux Forensics
Mark works as a Network administrator for SecureEnet Inc. His system runs on Mac OS X. He wants to boot his system from the Network Interface Controller (NIC). Which of the followi...
Mac OS Xstartup keysNIC network bootsnag keys - Question #180Advanced Incident Response & Digital Forensics Fundamentals
Which of the following provides high availability of data?
RAIDhigh availabilitydata redundancystorage resilience - Question #181Advanced Mac & Linux Forensics
You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to run a command that forces all the unwritten blocks in the buffer cache to be...
Unix commandssync commandbuffer cachedisk write operations - Question #182Memory Forensics & Anti-Forensics Detection
John used to work as a Network Administrator for We-are-secure Inc. Now he has resigned from the company for personal reasons. He wants to send out some secret information of the c...
steganographydata hidingimage file covert channelanti-forensics technique - Question #183File System & Registry Forensics
Which of the following statements is NOT true about the file slack spaces in Windows operating system?
file slack spacecluster sizeWindows file systemdata remnants - Question #184Advanced Incident Response & Digital Forensics Fundamentals
Adam works as a Security Administrator for Umbrella Technology Inc. He reported a breach in security to his senior members, stating that "security defenses has been breached and ex...
VPN security breachincident responseBEAST Trojanremote access control - Question #185Advanced Incident Response & Digital Forensics Fundamentals
Adam works as a Computer Hacking Forensic Investigator in a law firm. He has been assigned with his first project. Adam collected all required evidences and clues. He is now requir...
forensic report writinginvestigative report guidelinescourt documentationevidence presentation - Question #186Advanced Incident Response & Digital Forensics Fundamentals
Which of the following password cracking attacks is based on a pre-calculated hash table to retrieve plain text passwords?
rainbow table attackpassword crackingpre-calculated hasheshash tables - Question #187Advanced Windows Artifacts & Browser Forensics
Allen works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate a computer, which is used by the suspect to sexually harass...
Helix LiveMessenPassinstant messenger forensicspassword recovery tools - Question #188Advanced Incident Response & Digital Forensics Fundamentals
You work as a Computer Hacking Forensic Investigator for SecureNet Inc. You want to investigate Cross-Site Scripting attack on your company's Website. Which of the following method...
XSS investigationweb proxy analysisserver log reviewweb attack forensics - Question #189Advanced Incident Response & Digital Forensics Fundamentals
Which of the following Incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an ente...
incident handling phasespreparation phaseincident response lifecyclesecurity planning - Question #190Advanced Incident Response & Digital Forensics Fundamentals
Which of the following representatives of incident response team takes forensic backups of the systems that are the focus of the incident?
incident response teamforensic backupIR rolestechnical representative - Question #191Advanced Incident Response & Digital Forensics Fundamentals
Brutus is a password cracking tool that can be used to crack the following authentications: * HTTP(BasicAuthentication) * HTTP(HTMLForm/CGI) * POP3 (Post Office Protocol v3) * FTP(...
password crackingdictionary attackhybrid attackbrute force - Question #192File System & Registry Forensics
Rick works as a Network Administrator for uCertify Inc. He takes a backup of some important compressed files on an NTFS partition, using the Windows 2000 Backup utility. Rick resto...
NTFS compressionFAT32file system attributesWindows backup - Question #193Advanced Incident Response & Digital Forensics Fundamentals
Which of the following hardware devices prevents broadcasts from crossing over subnets?
network devicesrouterbroadcast domainsubnets - Question #194File System & Registry Forensics
Which of the following statements about the compression feature of the NTFS file system are true? Each correct answer represents a complete solution. Choose two.
NTFS compressionfile system featuresvolumesfolders - Question #195Advanced Mac & Linux Forensics
Which of the following statements is true for a file in the UNIX operating system?
UNIX file systemfile definitionLinux basics - Question #197Advanced Mac & Linux Forensics
You want to retrieve information whether your system is in promiscuous mode or not. Which of the following commands will you use? Each correct answer represents a complete solution...
promiscuous modenetwork forensicsLinux commandsifconfig - Question #198File System & Registry Forensics
You are responsible for tech support at your company. You have been instructed to make certain that all desktops support file and folder encryption. Which file system should you us...
NTFSEFS encryptionfile systemWindows XP - Question #199File System & Registry Forensics
Which of the following file systems supports disk quotas?
NTFSdisk quotasfile system featuresFAT32 - Question #200Advanced Windows Artifacts & Browser Forensics
Which of the following tools in Helix Windows Live is used to reveal the database password of password protected MDB files created using Microsoft Access or with Jet Database Engin...
Helix toolkitforensic toolspassword recoveryMDB files - Question #201Advanced Mac & Linux Forensics
You work as a Network Administrator for Perfect Solutions Inc. The company has a Linux-based network. You are creating a user account by using the USERADD command. Which of the fol...
Linux user managementUSERADDuser IDreserved accounts - Question #202Advanced Mac & Linux Forensics
John works as a professional Ethical Hacker. He has been assigned the project of testing the chmod -rwSr----- secure.c Considering the above scenario, which of the following statem...
Linux file permissionschmodSUID bitspecial permissions - Question #203Advanced Mac & Linux Forensics
Which of the following directories contains administrative commands on a UNIX computer?
UNIX directoriessbinadministrative commandsLinux file system - Question #204Advanced Incident Response & Digital Forensics Fundamentals
When you start your computer, Windows operating system reports that the hard disk drive has bad sectors. What will be your first step in resolving this issue?
hard diskbad sectorsSCANDISKdisk recovery - Question #205File System & Registry Forensics
Adam, a malicious hacker, hides a hacking tool from a system administrator of his company by using Alternate Data Streams (ADS) feature. Which of the following statements is true i...
Alternate Data StreamsNTFSanti-forensicsdata hiding - Question #206Advanced Incident Response & Digital Forensics Fundamentals
Which of the following classes of hackers describes an individual who uses his computer knowledge for breaking security laws, invading privacy, and making information systems insec...
hacker typesblack hatethicscybersecurity - Question #207Advanced Mac & Linux Forensics
Which of the following files contains the salted passwords in the Linux operating system?
Linux passwordsshadow filepassword storagesalted passwords - Question #208Threat Hunting & Timeline Analysis
You want to perform passive footprinting against we-are-secure Inc. Web server. Which of the following tools will you use?
passive footprintingNetcraftreconnaissanceweb server