Pay attention to our Valid and Useful Exam Reviews and take our Exam Torrent as your Study Material. With little time and energy investment, you have a High Efficiency Study experience. Pass your Actual Test with the help of our Actual Reviews.

[Jan-2022] The Best GIAC Information Security GCFA Professional Exam Questions [Q175-Q196]

Share

[Jan-2022] The Best GIAC Information Security GCFA Professional Exam Questions

Try 100% Updated GCFA Exam Questions [2022]


GIAC GCFA Exam Syllabus Topics:

TopicDetails
Enterprise Environment Incident Response- The candidate will demonstrate an understanding of the steps of the incident response process, attack progression, and adversary fundamentals and how to rapidly assess and analyze systems in an enterprise environment scaling tools to meet the demands of large investigations.
Volatile Data Artifact Analysis of Windows Events- The candidate will demonstrate an understanding of abnormal activity within the structure of Windows memory and be able to identify artifacts such as malicious processes, suspicious drivers and malware techniques such as code injection and rootkits.
Introduction to Volatile Data Forensics- The candidate will demonstrate an understanding of how and when to collect volatile data from a system and how to document and preserve the integrity of volatile evidence.
Introduction to File System Timeline Forensics- The candidate will demonstrate an understanding of the methodology required to collect and process timeline data from a Windows system.
File System Timeline Artifact Analysis- The candidate will demonstrate an understanding of the Windows filesystem time structure and how these artifacts are modified by system and user activity.
NTFS Artifact Analysis- The candidate will demonstrate an understanding of core structures of the Windows filesystems, and the ability to identify, recover, and analyze evidence from any file system layer, including the data storage layer, metadata layer, and filename layer.
Identification of Normal System and User Activity- The candidate will demonstrate an understanding of the techniques required to identify, document, and differentiate normal and abnormal system and user activity using memory and disk resident artifacts.
Identification of Malicious System and User Activity- The candidate will demonstrate an understanding of the techniques required to identify and document indicators of compromise on a system, detect malware and attacker tools, attribute activity to events and accounts, and identify and compensate for anti-forensic actions using memory and disk resident artifacts.
Volatile Data Artifact Analysis of Malicious Events- The candidate will demonstrate an understanding of abnormal activity within the structure of Windows memory and be able to identify artifacts such as malicious processes, suspicious drivers and malware techniques such as code injection and rootkits.
Windows Artifact Analysis- The candidate will demonstrate an understanding of Windows system artifacts and how to collect and analyze data such as system back up and restore data and evidence of application execution.


Topics Tested in GCFA Evaluation

When they decide to take the GCFA test, the candidates should check carefully the topics included in the blueprint. Any individual who manages to demonstrate the following acumen will have higher chances to pass the GCFA exam from the first attempt:

  • Demonstrating that he/she knows how to manage the structure file system associated with Windows infrastructure;
  • Demonstrating how to choose the right moment for collecting the timeline data when operating in a Windows system;
  • Gaining experience in working with the forensics-related to the file system timeline when they operate a Windows system;
  • Becoming able to recover and quickly analyze different types of data such as filename or metadata layers;
  • Getting the gist of is the techniques that a specialist should take to document the user’s activity and quickly identify the difference between an abnormal and normally working system;
  • Demonstrating that candidates can develop a comprehensive Windows analysis on artifacts and becoming able to collect restoration and backup data.
  • Immediately identifying the necessary techniques to prevent malicious systems from appearing and monitoring the user’s activity;
  • Identifying any abnormal activity in Windows memory’s structure and immediately identifying different types of artifacts like suspicious drivers or malicious processes;
  • Understanding the phases that should be taken in managing an incident response in an enterprise environment;

 

NEW QUESTION 175
Maria works as a professional Ethical Hacker. She recently got a project to test the security of www.we- are-secure.com. Arrange the three pre-test phases of the attack to test the security of weare-secure.
Select and Place:

Answer:

Explanation:

 

NEW QUESTION 176
Which of the following is a formula, practice, process, design, instrument, pattern, or compilation of information which is not generally known, but by which a business can obtain an economic advantage over its competitors?

  • A. Trade secret
  • B. Copyright
  • C. Cookie
  • D. Utility model

Answer: A

 

NEW QUESTION 177
Which of the following file systems contains hardware settings of a Linux computer?

  • A. /home
  • B. /var
  • C. /proc
  • D. /etc

Answer: C

Explanation:
Section: Volume A

 

NEW QUESTION 178
Peter works as a Computer Hacking Forensic Investigator for SecureEnet Inc. He has been assigned with a project of investigating a disloyal employee who is accused of stealing secret data from the company and selling it to the competitor company. Peter is required to collect proper evidences and information to present before the court for prosecution. Which of the following parameters is necessary for successful prosecution of this corporate espionage?

  • A. To present the evidences before the court.
  • B. To prove that the information has a value.
  • C. To submit investigative report to senior officials.
  • D. To prove that the data belongs to the company.

Answer: B

 

NEW QUESTION 179
Nathan works as a Computer Hacking Forensic Investigator for SecureEnet Inc. He uses Visual TimeAnalyzer software to track all computer usage by logging into individual users account or specific projects and compile detailed accounts of time spent within each program. Which of the following functions are NOT performed by Visual TimeAnalyzer?
Each correct answer represents a complete solution. Choose all that apply.

  • A. It monitors all user data such as passwords and personal documents.
  • B. It gives parents control over their children's use of the personal computer.
  • C. It tracks work time, pauses, projects, costs, software, and internet usage.
  • D. It records specific keystrokes and run screen captures as a background process.

Answer: A,D

 

NEW QUESTION 180
John works as a Network Security Professional. He is assigned a project to test the security of www.we- are-secure.com. He is working on the Linux operating system and wants to install an Intrusion Detection System on the We-are-secure server so that he can receive alerts about any hacking attempts. Which of the following tools can John use to accomplish the task?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Tripwire
  • B. Snort
  • C. Samhain
  • D. SARA

Answer: B,C

 

NEW QUESTION 181
Joseph works as a Web Designer for WebTech Inc. He creates a Web site and wants to protect it from lawsuits. Which of the following steps will he take to accomplish the task?
Each correct answer represents a part of the solution. Choose all that apply.

  • A. Restrict customers according to their locations.
  • B. Restrict the access to the site.
  • C. Restrict shipping in certain areas.
  • D. Restrict the transfer of information.

Answer: A,B,C

 

NEW QUESTION 182
Victor works as a professional Ethical Hacker for SecureNet Inc. He wants to use Steganographic file system method to encrypt and hide some secret information. Which of the following disk spaces will he use to store this secret information?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Unused Sectors
  • B. Dumb space
  • C. Hidden partition
  • D. Slack space

Answer: A,C,D

 

NEW QUESTION 183
Which utility enables you to access files from a Windows .CAB file?

  • A. ACCESS.EXE
  • B. WINZIP.EXE
  • C. EXTRACT.EXE
  • D. XCOPY.EXE

Answer: C

 

NEW QUESTION 184
You work as a Computer Hacking Forensic Investigator for SecureNet Inc. You want to investigate Cross-Site Scripting attack on your company's Website. Which of the following methods of investigation can you use to accomplish the task?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Use a Web proxy to view the Web server transactions in real time and investigate any communication with outside servers.
  • B. Look at the Web servers logs and normal traffic logging.
  • C. Review the source of any HTML-formatted e-mail messages for embedded scripts or links in the URL to the company's site.
  • D. Use Wireshark to capture traffic going to the server and then searching for the requests going to the input page, which may give log of the malicious traffic and the IP address of the source.

Answer: A,B,C

 

NEW QUESTION 185
Normally, RAM is used for temporary storage of data. But sometimes RAM data is stored in the hard disk, what is this method called?

  • A. Virtual memory
  • B. Cache memory
  • C. Static memory
  • D. Volatile memory

Answer: A

 

NEW QUESTION 186
Peter works as a Computer Hacking Forensic Investigator for SecureEnet Inc. He has been assigned with a project of investigating a disloyal employee who is accused of stealing secret data from the company and selling it to the competitor company. Peter is required to collect proper evidences and information to present before the court for prosecution. Which of the following parameters is necessary for successful prosecution of this corporate espionage?

  • A. To present the evidences before the court.
  • B. To prove that the information has a value.
  • C. To submit investigative report to senior officials.
  • D. To prove that the data belongs to the company.

Answer: B

 

NEW QUESTION 187
Which of the following statements is NOT true about FAT16 file system?
Each correct answer represents a complete solution. Choose all that apply.

  • A. FAT16 does not support file-level security.
  • B. FAT16 file system works well with large disks because the cluster size increases as the disk partition size increases.
  • C. FAT16 file system supports file-level compression.
  • D. FAT16 file system supports Linux operating system.

Answer: B,C

 

NEW QUESTION 188
In Linux, which of the following files describes the processes that are started up during boot up?

  • A. /etc/passwd
  • B. /etc/shadow
  • C. /etc/inittab
  • D. /etc/profile

Answer: C

 

NEW QUESTION 189
Which of the following components are usually found in an Intrusion detection system (IDS)?
Each correct answer represents a complete solution. Choose two.

  • A. Console
  • B. Sensor
  • C. Modem
  • D. Firewall
  • E. Gateway

Answer: A,B

 

NEW QUESTION 190
Which of the following statements best describes the consequences of the disaster recovery plan test?

  • A. If no deficiencies were found during the test, then the test was probably flawed.
  • B. The results of the test should be kept secret.
  • C. If no deficiencies were found during the test, then the plan is probably perfect.
  • D. The plan should not be changed no matter what the results of the test would be.

Answer: A

Explanation:
Section: Volume B

 

NEW QUESTION 191
You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate Plagiarism occurred in the source code files of C#. Which of the following tools will you use to detect the software plagiarism?

  • A. Turnitin
  • B. Jplag
  • C. VAST
  • D. SCAM

Answer: B

 

NEW QUESTION 192
Which utility enables you to access files from a Windows .CAB file?

  • A. ACCESS.EXE
  • B. WINZIP.EXE
  • C. EXTRACT.EXE
  • D. XCOPY.EXE

Answer: C

Explanation:
Section: Volume B
Explanation/Reference:

 

NEW QUESTION 193
Nathan works as a professional Ethical Hacker. He wants to see all open TCP/IP and UDP ports of his computer. Nathan uses the netstat command for this purpose but he is still unable to map open ports to the running process with PID, process name, and path. Which of the following commands will Nathan use to accomplish the task?

  • A. fport
  • B. ping
  • C. Pslist
  • D. Psloggedon

Answer: A

 

NEW QUESTION 194
Which of the following registry hives contains information about all users who have logged on to the system?

  • A. HKEY_CLASSES_ROOT
  • B. HKEY_CURRENT_USERS
  • C. HKEY_CURRENT_CONFIG
  • D. HKEY_USERS

Answer: D

 

NEW QUESTION 195
Which of the following Windows XP system files handles memory management, I/O operations, and interrupts?

  • A. Win32k.sys
  • B. Kernel32.dll
  • C. Ntoskrnl.exe
  • D. Advapi32.dll

Answer: B

Explanation:
Section: Volume B

 

NEW QUESTION 196
......

GCFA Exam Questions Get Updated [2022] with Correct Answers: https://www.examsreviews.com/GCFA-pass4sure-exam-review.html

Pass GCFA Exam - Real Questions & Answers: https://drive.google.com/open?id=1gjRzpg55vSDXUNvkmpUuFepOO64ehytf