GCFA Exam Questions
314 real GCFA exam questions with expert-verified answers and explanations. Page 6 of 7.
- Question #261Advanced Incident Response & Digital Forensics Fundamentals
Which status is a problem, assigned when its cause has been recognized?
known errorproblem managementITILincident lifecycle - Question #262Threat Hunting & Timeline Analysis
John works as a Network Security Professional. He is assigned a project to test the security of Intrusion Detection System on the We-are-secure server so that he can receive alerts...
IDS testingSnortSamhainintrusion detection - Question #263Advanced Incident Response & Digital Forensics Fundamentals
Which of the following laws enacted in United States makes it illegal for an Internet Service Provider (ISP) to allow child pornography to exist on Web sites?
cyber lawISP liabilitychild exploitationUS legislation - Question #264Advanced Incident Response & Digital Forensics Fundamentals
Peter works as a Security Administrator for SecureEnet Inc. He observes that the database server of the company has been compromised and the data is stolen. Peter immediately wants...
law enforcementcybercrime reportingUS Secret Serviceincident escalation - Question #265Advanced Incident Response & Digital Forensics Fundamentals
Sandra, an expert computer user, hears five beeps while booting her computer that has AMI BIOS; and after that her computer stops responding. Sandra knows that during booting proce...
POST beep codesAMI BIOShardware diagnosticsprocessor failure - Question #266Advanced Mac & Linux Forensics
Sam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate a compromised system, which runs on Linux operating system. Sa...
Linux directory structure/sbinsystem binariesLinux forensics - Question #267File System & Registry Forensics
Which of the following file systems are supported by Windows 2000 operating systems? Each correct answer represents a complete solution. Choose all that apply.
NTFSFAT32CDFSWindows file systems - Question #269Advanced Incident Response & Digital Forensics Fundamentals
You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate the DoS attack on a computer network of SecureEnet Inc. Which o...
DoS investigationnetwork traffic analysiscrash dumpsnetwork forensics - Question #270Advanced Mac & Linux Forensics
You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to print the super block and block the group information for the filesystem pre...
dumpe2fsUnix filesystemsuperblockblock group info - Question #271File System & Registry Forensics
Which of the following are advantages of NTFS file system over FAT32 and FAT? Each correct answer represents a part of the solution. Choose two.
NTFSFAT32EFSfile permissions - Question #272File System & Registry Forensics
You want to change the attribute of a file named ACE.TXT to Hidden. Which command line will enable you to set the attribute?
ATTRIB commandfile attributeshidden filesWindows CLI - Question #273Advanced Incident Response & Digital Forensics Fundamentals
You are the Security Consultant and have been hired to check security for a client's network. Your client has stated that he has many concerns but the most critical is the security...
vulnerability scanningweb application securitysecurity assessmentnetwork security - Question #275Advanced Mac & Linux Forensics
Jason, a game lover, owns an Apple's iPod nano. He wants to play games on his iPod. He also wants to improve the quality of the audio recording of his iPod. Which of the following...
iPodLinuxmobile devicefirmwareembedded systems - Question #276Advanced Incident Response & Digital Forensics Fundamentals
You work as a Network Administrator for NetTech Inc. The company has a network that consists of 200 client computers and ten database servers. One morning, you find that an unautho...
evidence preservationincident responsechain of custodylog files - Question #277Advanced Incident Response & Digital Forensics Fundamentals
Which of the following functionality within the Autopsy browser is specifically designed to aid in case management?
Autopsyforensic toolsimage integritycase management - Question #278Memory Forensics & Anti-Forensics Detection
Which of the following is a nonvolatile form of memory that can be reprogrammed by using a special programming device, and need not to be removed from the PC to be reprogrammed?
EEPROMnonvolatile memorymemory typesfirmware - Question #279Threat Hunting & Timeline Analysis
Your friend plans to install a Trojan on your computer. He knows that if he gives you a new version of chess.exe, you will definitely install the game on your computer. He picks up...
TrojanBack Orificemalware detectionremote access - Question #280Advanced Incident Response & Digital Forensics Fundamentals
The promiscuous mode is a configuration of a network card that makes the card pass all traffic it receives to the central processing unit rather than just packets addressed to it....
promiscuous modenetwork snifferpacket captureNIC - Question #282Advanced Mac & Linux Forensics
In Linux, which of the following files describes the processes that are started up during boot up?
inittabLinux boot processstartup processesrunlevels - Question #283File System & Registry Forensics
Which of the following registry hives stores information about the file extensions that are mapped to their corresponding applications?
HKEY_CLASSES_ROOTregistry hivesfile extensionsWindows registry - Question #284Advanced Incident Response & Digital Forensics Fundamentals
An organization wants to mitigate the risks associated with the lost or stolen laptops and the associated disclosure laws, while reporting data breaches. Which of the following sol...
whole disk encryptiondata protectionlaptop securitydata breach disclosure - Question #285Advanced Incident Response & Digital Forensics Fundamentals
Which of the following cryptographic methods are used in EnCase to ensure the integrity of the data, which is acquired for the investigation? Each correct answer represents a compl...
EnCaseMD5CRCforensic data integrity - Question #286Advanced Mac & Linux Forensics
Which of the following fsck commands will you use to check all filesystems listed in /etc/fstab?
fsckLinux filesystem check/etc/fstabLinux commands - Question #287File System & Registry Forensics
Which of the following switches of the XCOPY command copies file ownerships and NTFS permissions on files while copying the files?
XCOPYNTFS permissionsfile ownershipWindows CLI - Question #288Advanced Incident Response & Digital Forensics Fundamentals
Which of the following sections of United States Economic Espionage Act of 1996 criminalizes the misappropriation of trade secrets related to or included in a product that is produ...
Economic Espionage Acttrade secretsUS lawTitle 18 USC 1832 - Question #289Advanced Windows Artifacts & Browser Forensics
Which of the following statements about the NTDETECT.COM file is true? Each correct answer represents a complete solution. Choose three.
NTDETECT.COMWindows boot processWindows NT/2000startup files - Question #291Advanced Incident Response & Digital Forensics Fundamentals
Which of the following can be monitored by using the host intrusion detection system (HIDS)? Each correct answer represents a complete solution. Choose two.
HIDSfile system integritysystem monitoringintrusion detection - Question #292Advanced Incident Response & Digital Forensics Fundamentals
Which of the following types of attack can guess a hashed password?
brute force attackpassword crackinghashed passwordsauthentication - Question #293Advanced Mac & Linux Forensics
John works as a professional Ethical Hacker. He has been assigned a project to test the security chmod 741 secure.c Considering the above scenario, which of the following statement...
chmodoctal permissionsLinux file permissionsaccess control - Question #294File System & Registry Forensics
You work as a Network Administrator for Net World International. Rick, a Sales Manager, complains that his Windows 98 computer is not displaying the taskbar. You reboot his compute...
Windows registryregistry editorregistry keysWindows 98 - Question #295Advanced Mac & Linux Forensics
Which of the following files in LILO booting process of Linux operating system stores the location of Kernel on the hard drive?
LILO bootloaderLinux boot processkernel locationboot map - Question #296Advanced Incident Response & Digital Forensics Fundamentals
Joseph works as a Software Developer for WebTech Inc. He wants to protect the algorithms and the techniques of programming that he uses in developing an application. Which of the f...
patent lawintellectual propertysoftware protectionlegal frameworks - Question #297Advanced Mac & Linux Forensics
What is the name of the Secondary IDE slave, fourth partition in Linux operating system according to the Linux naming convention?
Linux disk namingIDE devicespartition namingdevice conventions - Question #298Advanced Mac & Linux Forensics
John works as a Network Administrator for Perfect Solutions Inc. The company has a Linux-based network. John is working as a root user on the Linux operating system. He wants to fo...
syslog.confLinux loggingremote log forwardingkernel messages - Question #299File System & Registry Forensics
You use the FAT16 file system on your Windows 98 computer. You want to upgrade to the FAT32 file system. What is the advantage of the FAT32 file system over FAT16 file system? Each...
FAT32FAT16file system comparisondisk allocation - Question #300Threat Hunting & Timeline Analysis
John works as a professional Ethical Hacker. He is assigned a project to test the security of We-are- secure Web site and receives the following error message: Microsoft OLE DB Pro...
SQL injectionOLE DB errorweb vulnerability identificationattack recognition - Question #301Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is NOT an example of passive footprinting?
passive footprintingactive reconnaissanceport scanningOSINT - Question #302File System & Registry Forensics
Your Windows XP hard drive has 2 partitions. The system partition is NTFS and the other is FAT. You wish to encrypt a folder created on the system partition for the purpose of data...
EFSNTFS encryptionFAT limitationsfile system encryption - Question #303Advanced Mac & Linux Forensics
Which of the following files starts the initialization process in booting sequence of the Linux operating system?
Linux initboot sequenceinitialization processLinux startup - Question #304Advanced Mac & Linux Forensics
Which of the following Linux file systems is a journaled file system?
ext3journaled file systemLinux file systemsext2 vs ext3 - Question #305Advanced Incident Response & Digital Forensics Fundamentals
Which of the following Acts enacted in United States amends Civil Rights Act of 1964, providing technical changes affecting the length of time allowed to challenge unlawful seniori...
Civil Rights Act 1991US legislationlegal compliancedigital forensics law - Question #306Advanced Incident Response & Digital Forensics Fundamentals
You work as a Forensic Investigator. Which of the following rules will you follow while working on a case? Each correct answer represents a part of the solution. Choose all that ap...
chain of custodyevidence handlingforensic rulesinvestigation procedures - Question #307Advanced Windows Artifacts & Browser Forensics
Based on the case study, to implement more security, which of the following additional technologies should you implement for laptop computers? (Click the Exhibit button on the tool...
EFSdigital certificateslaptop securityencryption technologies - Question #308File System & Registry Forensics
You work as a Network Administrator for Blue Well Inc. Your company's network has a Windows 2000 server with the FAT file system. This server stores sensitive data. You want to enc...
EFSFAT file systemNTFS requirementencryption constraints - Question #309Threat Hunting & Timeline Analysis
Which of the following types of virus makes changes to a file system of a disk?
cluster virusfile system modificationvirus typesmalware classification - Question #310Memory Forensics & Anti-Forensics Detection
Which of the following switches is used with Pslist command on the command line to show the statistics for all active threads on the system, grouping these threads with their ownin...
Pslistprocess enumerationthread analysisCLI switches - Question #311File System & Registry Forensics
Which of the following methods can be used to start the Disk Defragmenter utility in Windows 9x? Each correct answer represents a complete solution. Choose two.
Disk DefragmenterWindows 9xsystem toolsfile system maintenance - Question #312Advanced Incident Response & Digital Forensics Fundamentals
Which two technologies should research groups use for secure VPN access while traveling? (Click the Exhibit button on the toolbar to see the case study.) Each correct answer repres...
VPN protocolsPPTPsmart cardsremote access security - Question #313File System & Registry Forensics
Which of the following file attributes are not available on a FAT32 partition? Each correct answer represents a complete solution. Choose two.
FAT32file attributescompressionencryption - Question #314Advanced Incident Response & Digital Forensics Fundamentals
Which of the following statutes is enacted in the U.S., which prohibits creditors from collecting data from applicants, such as national origin, caste, religion etc?
ECOAdata privacy lawlegal compliancefinancial data protection