GCFE Exam Questions
160 real GCFE exam questions with expert-verified answers and explanations. Page 3 of 4.
- Question #101
What forensic value does the analysis of 'link files' (.lnk) offer?
- Question #102
What role do 'system snapshots' play in forensic analysis of file activities?
- Question #103
Why is live data acquisition important in some forensic investigations?
- Question #104
Which event log is most useful for tracking user login attempts and potential unauthorized access?
- Question #105
What forensic value do Windows registry hives offer in the context of system analysis?
- Question #106
What is the significance of the Recycle Bin in forensic investigations of user activity?
- Question #107
What type of information does the analysis of Flash cookies (LSOs) typically yield in browser forensics?
- Question #108
You are investigating a case of data theft from a corporate server. The suspect accessed the server using a shared account. Which forensic techniques should you use to prove the su...
- Question #109
A forensic investigator needs to track USB devices connected to a corporate laptop involved in intellectual property theft. What steps should the investigator take to gather this e...
- Question #110
Which two user artifacts are critical for understanding a user's browsing habits?
- Question #111
What is the significance of 'shadow copies' in Windows in a forensic investigation?
- Question #112
Which Windows artifact stores details about USB devices that were plugged into a system?
- Question #113
What does the $MFT primarily track on NTFS systems?
- Question #114
Which Windows log contains failed and successful logon attempts?
- Question #115
What is the forensic relevance of 'alternate data streams' in NTFS filesystems?
- Question #116
Which of the following browser artifacts can help identify the websites visited by a user?
- Question #117
In the context of system and device analysis, why is 'network traffic monitoring' crucial?
- Question #118
Why is the 'Last Known Good Configuration' data important in forensic analysis of Windows systems?
- Question #119
Which of the following are critical artifacts for tracking user access to files in cloud storage applications like Dropbox and Google Drive? (Choose Two)
- Question #120
When analyzing browser data in Google Chrome, which files are useful for understanding download history? (Choose Two)
- Question #121
For forensic analysis, which file in Chrome provides insights into user actions regarding file downloads?
- Question #122
Which artifacts are essential for identifying URLs that were typed manually by a user during a browsing session? (Choose Two)
- Question #123
In digital forensics, why is the analysis of 'environment variables' crucial?
- Question #124
What type of forensic data can be extracted from a browser's cache?
- Question #125
You are investigating suspicious emails sent from a company employee's account. The employee denies sending them. What forensic techniques would you use to investigate the authenti...
- Question #126
What can be inferred from analyzing the 'Deleted Items' folder in email applications in a forensic context?
- Question #127
Which two artifacts are essential for tracking file access and modification times on a Windows system?
- Question #128
Which of the following is a primary forensic artifact found in web browsers that can help in identifying user activities?
- Question #129
What can be inferred from the analysis of 'executable files' in a digital forensic investigation? (Choose Two)
- Question #130
A forensic investigator is analyzing a Windows system suspected of containing malware. The user claims they did not install any suspicious programs. Which artifacts would you analy...
- Question #131
Which artifact is typically used to determine application execution on Windows?
- Question #132
The Windows Recycle Bin stores deleted file metadata in which file?
- Question #133
Which browser artifact contains visited URLs and download history for Microsoft Edge/IE?
- Question #134
What Windows Registry hive would you analyze for user-specific evidence?
- Question #135
Which of the following artifacts from cloud storage services is most valuable in determining when a file was uploaded to the cloud?
- Question #136
How can the analysis of 'file metadata' aid in understanding the timeline of events on a system?
- Question #137
What role does the Master File Table (MFT) play in the forensic analysis of NTFS filesystems?
- Question #138
Which Windows artifact is primarily used to store metadata about files, including the file creation and modification times?
- Question #139
How does analyzing 'file access times' contribute to forensic investigations?
- Question #140
In the context of digital forensics, how does analyzing 'log files' of a program help in an investigation?
- Question #141
What is the primary purpose of Windows event logs in the context of digital forensics?
- Question #142
How does examining 'startup folder contents' help in forensic investigations?
- Question #143
What is the primary purpose of creating a forensic image of a hard drive?
- Question #144
Why is the analysis of 'boot logs' critical in digital forensics?
- Question #145
How can an analyst use 'security logs' to detect unauthorized access attempts?
- Question #146
How do forensic analysts use slack space in the context of digital investigations?
- Question #147
What does the analysis of the 'Index.dat' file provide in Internet Explorer browser forensics?
- Question #148
An examiner wants to identify persistence via Run keys. Which Registry location should they check?
- Question #149
Which timeline artifact records the time files were created, accessed, modified and changed?
- Question #150
Which forensic imaging principle maintains data integrity?