GCFA Exam Questions
314 real GCFA exam questions with expert-verified answers and explanations. Page 5 of 7.
- Question #209Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is a formula, practice, process, design, instrument, pattern, or compilation of information which is not generally known, but by which a business can obtain...
trade secretintellectual propertylegal conceptsbusiness law - Question #210Advanced Incident Response & Digital Forensics Fundamentals
John works as a professional Ethical Hacker. He has been assigned a project to test the security local disk and obtains all the files on the Web site. Which of the following techni...
web rippingreconnaissanceethical hackingdisk enumeration - Question #211File System & Registry Forensics
You work as a Network Administrator for NetTech Inc. To ensure the security of files, you encrypt data files using Encrypting File System (EFS). You want to make a backup copy of t...
EFSNTFSfile encryptionbackup integrity - Question #212Memory Forensics & Anti-Forensics Detection
Victor works as a professional Ethical Hacker for SecureEnet Inc. He has been assigned a job to test an image, in which some secret information is hidden, using Steganography. Vict...
steganographyactive attacksimage manipulationanti-forensics - Question #213Advanced Incident Response & Digital Forensics Fundamentals
Which of the following needs to be documented to preserve evidences for presentation in court?
chain of custodyevidence preservationcourt admissibilitydocumentation - Question #214Advanced Incident Response & Digital Forensics Fundamentals
Mark is taking a data backup during non-working hours from a remote computer on the network by using the Backup utility. What will he do to ensure that the backup has no errors?
backup verificationdata integrityremote backuperror checking - Question #215Advanced Incident Response & Digital Forensics Fundamentals
A Web-based credit card company had collected financial and personal details of Mark before issuing him a credit card. The company has now provided Mark's financial and personal de...
privacy lawdata sharingpersonal informationlegal compliance - Question #216Advanced Incident Response & Digital Forensics Fundamentals
Which of the following precautionary steps are taken by the supervisors or employers to avoid sexual harassment in workplace? Each correct answer represents a complete solution. Ch...
workplace policycomplaint mechanismHR complianceincident procedure - Question #217Advanced Incident Response & Digital Forensics Fundamentals
Which of the following components are usually found in an Intrusion detection system (IDS)? Each correct answer represents a complete solution. Choose two.
IDS componentsintrusion detectionsensorconsole - Question #218File System & Registry Forensics
You work as a Network Administrator for Perfect Solutions Inc. You have to install Windows 2000 on a computer that will work as a file server. You have to format the hard disk of t...
NTFSfile system encryptionEFSfile server - Question #219Advanced Incident Response & Digital Forensics Fundamentals
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate a multimedia enabled mobile phone, which is suspected to be u...
mobile forensicsDevice Seizuredeleted data recoverymobile evidence - Question #220Threat Hunting & Timeline Analysis
Adam, a malicious hacker performs an exploit, which is given below: ################################################################# $port = 53; # Spawn cmd.exe on port X $your =...
exploit analysisMSADC exploitFTP-based attackcommand shell spawn - Question #221Advanced Incident Response & Digital Forensics Fundamentals
Which of the following log files are used to collect evidences before taking the bit-stream image of the BlackBerry? Each correct answer represents a complete solution. Choose all...
BlackBerry forensicsmobile log filesevidence collectionbit-stream imaging - Question #223File System & Registry Forensics
On your dual booting computer, you want to set Windows 98 as the default operating system at startup. In which file will you define this?
BOOT.INIdual bootWindows startupboot configuration - Question #224Advanced Incident Response & Digital Forensics Fundamentals
Which of the following data is NOT listed as a volatile data in RFC 3227 list for Windows based system?
RFC 3227volatile dataorder of volatilityevidence collection - Question #225Threat Hunting & Timeline Analysis
Which of the following tools are used to determine the hop counts of an IP packet? Each correct answer represents a complete solution. Choose two.
tracertpinghop countTTL - Question #226File System & Registry Forensics
Which of the following statements is NOT true about FAT16 file system? Each correct answer represents a complete solution. Choose all that apply.
FAT16file system limitationscluster sizefile compression - Question #227Advanced Mac & Linux Forensics
You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to set the hard disk geometry parameters, cylinders, heads, and sectors. Which...
hdparmUnix disk commandshard disk geometryLinux administration - Question #228Advanced Incident Response & Digital Forensics Fundamentals
Which of the following statements about SD cards are true? Each correct answer represents a complete solution. Choose two.
SD cardnon-volatile memorymobile devicesdigital media - Question #230Advanced Incident Response & Digital Forensics Fundamentals
Which of the following types of cyber stalking damage the reputation of their victim and turn other people against them by setting up their own Websites, blogs or user pages for th...
cyber stalkingfalse accusationsvictim reputationonline harassment - Question #231Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is used to back up forensic evidences or data folders from the network or locally attached hard disk drives?
forensic evidence backupFAR systemforensic toolsdata acquisition - Question #232Advanced Incident Response & Digital Forensics Fundamentals
Which of the following encryption methods use the RC4 technology? Each correct answer represents a complete solution. Choose all that apply.
RC4 encryptionWEPTKIPwireless encryption - Question #233Advanced Incident Response & Digital Forensics Fundamentals
Which of the following types of firewall ensures that the packets are part of the established session?
stateful inspectionfirewall typessession trackingnetwork security - Question #234File System & Registry Forensics
You work as a Network Administrator for McNeel Inc. You want to encrypt each user's MY DOCUMENTS folder. You decide to use Encrypting File System (EFS). You plan to write a script...
EFSCIPHER commandfile encryptionWindows tools - Question #235Memory Forensics & Anti-Forensics Detection
John works as a Technical Support Executive in ABC Inc. The company's network consists of ten computers with Windows XP professional installed on all of them. John is working with...
hibernationhiberfil.sysmemory persistencevolatile data - Question #236File System & Registry Forensics
Which of the following tables is formed by NTFS file system to keep the track of files, to store metadata, and their location?
NTFSMaster File Tablefile metadatafile system structure - Question #237Advanced Incident Response & Digital Forensics Fundamentals
Which of the following layers protocols handles file transfer and network management?
OSI modelapplication layerfile transfer protocolsnetwork management - Question #238Advanced Windows Artifacts & Browser Forensics
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate computer of an unfaithful employee of SecureEnet Inc. Suspect...
swap filesslack spacehidden partitionsWindows evidence sources - Question #239Advanced Incident Response & Digital Forensics Fundamentals
What are the purposes of audit records on an information system? Each correct answer represents a complete solution. Choose two.
audit recordsinvestigationtroubleshootinginformation systems - Question #240Advanced Incident Response & Digital Forensics Fundamentals
Peter, an expert computer user, attached a new sound card to his computer. He then restarts the computer, so that the BIOS can scan the hardware changes. What will be the memory ra...
BIOSROM memory rangehardware scanningsystem memory - Question #241Advanced Incident Response & Digital Forensics Fundamentals
John works as a professional Ethical Hacker. He has been assigned a project to test the security he can bypass the firewall of the We-are-secure server. Which of the following tool...
firewall bypassFpipeport redirectionpenetration testing - Question #242Advanced Mac & Linux Forensics
You work as a Network Administrator for Tech Perfect Inc. The company has a Linux-based network. Users complain that they are unable to access resources on the network. However, th...
BINDDNS resolutionLinux servicesnetwork troubleshooting - Question #243Advanced Incident Response & Digital Forensics Fundamentals
Which of the following standard technologies is not used to interface hard disk with the computer?
hard disk interfacesUSBSCSIIDE/ATA - Question #244Advanced Mac & Linux Forensics
Which of the following commands is used to enforce checking of a file system even if the file system seems to be clean?
e2fsckfile system checkLinux forensicsfsck commands - Question #245Advanced Incident Response & Digital Forensics Fundamentals
You are responsible for all computer security at your company. This includes initial investigation into alleged unauthorized activity. Which of the following are possible results o...
chain of custodyimproper evidence handlingprosecutionlegal implications - Question #246Advanced Incident Response & Digital Forensics Fundamentals
Which of the following tools works by using standard set of MS-DOS commands and can create an MD5 hash of an entire drive, partition, or selected files?
DriveSpyMD5 hashdrive imagingforensic hashing - Question #247Advanced Incident Response & Digital Forensics Fundamentals
Peter works as a Computer Hacking Forensic Investigator for SecureEnet Inc. He has been assigned with a project of investigating a disloyal employee who is accused of stealing secr...
corporate espionageprosecution requirementsdata theftevidence value - Question #248Advanced Incident Response & Digital Forensics Fundamentals
Which of the following are known as the three laws of OPSEC? Each correct answer represents a part of the solution. Choose three.
OPSECoperational securitythreat awarenessinformation protection - Question #249Advanced Incident Response & Digital Forensics Fundamentals
Which of the following steps are generally followed in computer forensic examinations? Each correct answer represents a complete solution. Choose three.
forensic examination stepsevidence acquisitionauthenticationforensic analysis - Question #250Advanced Incident Response & Digital Forensics Fundamentals
Every network device contains a unique built in Media Access Control (MAC) address, which is used to identify the authentic device to limit the network access. Which of the followi...
MAC addressnetwork addressinghardware identification - Question #251Advanced Incident Response & Digital Forensics Fundamentals
Which of the following refers to the ability to ensure that the data is not modified or tampered with?
data integrityCIA triadinformation security - Question #252Advanced Incident Response & Digital Forensics Fundamentals
In which of the following security tests does the security testing team simulate as an employee or other person with an authorized connection to the organization's network?
penetration testinginternal network testingsecurity assessment - Question #253Advanced Incident Response & Digital Forensics Fundamentals
You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate Plagiarism occurred in the source code files of C#. Which of th...
source code forensicsplagiarism detectionforensic toolsJplag - Question #254Advanced Mac & Linux Forensics
You work as a Network Administrator for Perfect Solutions Inc. The company has a Linux-based network. You are working as a root user on the Linux operating system. While performing...
Linux commandslogin historyuser activity forensicslast command - Question #255Advanced Incident Response & Digital Forensics Fundamentals
Which of the following types of evidence is considered as the best evidence?
best evidence rulelegal evidenceevidence handlingdigital forensics - Question #256Advanced Mac & Linux Forensics
Which of the following commands can you use to create an ext3 file system? Each correct answer represents a complete solution. Choose two.
ext3 filesystemmkfsLinux filesystemdisk formatting - Question #257Advanced Windows Artifacts & Browser Forensics
You are the Security Consultant working with a client who uses a lot of outdated systems. Many of their clients PC's still have Windows 98. You are concerned about the security of...
LANMAN hashWindows 98 authenticationpassword hashinglegacy credentials - Question #258Advanced Incident Response & Digital Forensics Fundamentals
Adam works as a professional Computer Hacking Forensic Investigator, a project has been assigned to him to investigate and examine files present on suspect's computer. Adam uses a...
WinHexhex editorforensic toolsdeleted file recovery - Question #259File System & Registry Forensics
The Klez worm is a mass-mailing worm that exploits a vulnerability to open an executable attachment even in Microsoft Outlook's preview pane. The Klez worm gathers email addresses...
Klez wormregistry forensicsmalware artifactsWindows Address Book - Question #260Advanced Incident Response & Digital Forensics Fundamentals
Which of the following involves changing data prior to or during input to a computer in an effort to commit fraud?
data diddlinginput manipulationcomputer fraudattack types