GCFE Exam Questions
160 real GCFE exam questions with expert-verified answers and explanations. Page 4 of 4.
- Question #151
What is the forensic value of analyzing the 'Windows Event Viewer' in the context of system analysis?
- Question #152
During a forensic investigation, you need to reconstruct a user's browsing history from Firefox. The user is suspected of accessing unauthorized sites, but they have cleared their...
- Question #153
What is the significance of analyzing 'volatile memory' in a forensic investigation?
- Question #154
When examining browser artifacts, which of the following files are crucial for reconstructing a user's search history? (Choose Two)
- Question #155
You are conducting a forensic investigation on a Mozilla Firefox installation. The user has attempted to conceal their browsing activity by clearing the history. What browser files...
- Question #156
How does the examination of 'script files' used in system automation contribute to forensic analysis?
- Question #157
How can the analysis of 'USB device connection logs' aid in a forensic investigation?
- Question #158
Which event log would be most useful for understanding application failures or crashes? (Choose Two)
- Question #159
Why is it important to maintain the chain of custody in forensic investigations?
- Question #160
What forensic insights can be derived from analyzing 'archived files' on a system?