
Dumps Moneyack Guarantee - GCFA Dumps UpTo 50% Off
Updated Jun-2023 Pass GCFA Exam - Real Practice Test Questions
The GIAC GCFA certification is a highly respected certification in the field of digital forensics. It validates the skills and knowledge required to conduct complex digital investigations and is recognized by employers around the world. To prepare for the exam, candidates should take specialized training courses and use study materials and practice exams provided by GIAC. Achieving the GCFA certification can open up new career opportunities and increase earning potential.
NEW QUESTION # 187
Which two technologies should research groups use for secure VPN access while traveling? (Click the Exhibit button on the toolbar to see the case study.)
Each correct answer represents a complete solution. Choose two.
- A. Encrypting File System (EFS)
- B. PPTP
- C. SSL
- D. Smart cards
- E. Kerberos authentication
Answer: B,D
NEW QUESTION # 188
Which of the following statements about registry is true?
Each correct answer represents a complete solution. Choose three.
- A. It is a centralized configuration database that stores information related to a Windows computer.
- B. It was first introduced with Windows 95 operating system.
- C. It can be edited using SCANREG utility.
- D. It is divided in many areas known as hives.
Answer: A,B,D
NEW QUESTION # 189
Which of the following enables an inventor to legally enforce his right to exclude others from using his invention?
- A. Phishing
- B. Spam
- C. Artistic license
- D. Patent
Answer: D
NEW QUESTION # 190
Peter works as a Computer Hacking Forensic Investigator. He has been called by an organization to conduct a seminar to give necessary information related to sexual harassment within the work place. Peter started with the definition and types of sexual harassment. He then wants to convey that it is important that records of the sexual harassment incidents should be maintained, which helps in further legal prosecution.
Which of the following data should be recorded in this documentation?
Each correct answer represents a complete solution. Choose all that apply.
- A. Location of each incident
- B. Names of the victims
- C. Date and time of incident
- D. Nature of harassment
Answer: A,B,C
NEW QUESTION # 191
Which of the following types of attacks cannot be prevented by technical measures only?
- A. Ping flood attack
- B. Smurf DoS
- C. Social engineering
- D. Brute force
Answer: C
NEW QUESTION # 192
You work as a Network Administrator for Perfect Solutions Inc. The company has a Linux-based network.
You are creating a user account by using the USERADD command. Which of the following entries cannot be used for specifying a user ID?
Each correct answer represents a complete solution. Choose all that apply.
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A,B,C
NEW QUESTION # 193
Which of the following statements is NOT true about the file slack spaces in Windows operating system?
- A. File slack is the space, which exists between the end of the file and the end of the last cluster.
- B. File slack may contain data from the memory of the system.
- C. Large cluster size will decrease the volume of the file slack.
- D. It is possible to find user names, passwords, and other important information in slack.
Answer: C
Explanation:
Section: Volume B
NEW QUESTION # 194
John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we- are-secure.com. He copies the whole structure of the We-are-secure Web site to the local disk and obtains all the files on the Web site. Which of the following techniques is he using to accomplish his task?
- A. Eavesdropping
- B. Fingerprinting
- C. TCP FTP proxy scanning
- D. Web ripping
Answer: D
Explanation:
Section: Volume C
NEW QUESTION # 195
You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to fix partitions on a hard drive. Which of the following Unix commands can you use to accomplish the task?
- A. exportfs
- B. fdformat
- C. fdisk
- D. fsck
Answer: C
NEW QUESTION # 196
Which of the following tools can be used by a user to hide his identity?
Each correct answer represents a complete solution. Choose all that apply.
- A. Proxy server
- B. War dialer
- C. Anonymizer
- D. Rootkit
- E. IPchains
Answer: A,C,E
NEW QUESTION # 197
Adam works as a professional Computer Hacking Forensic Investigator, a project has been assigned to him to investigate and examine files present on suspect's computer. Adam uses a tool with the help of which he can examine recovered deleted files, fragmented files, and other corrupted data. He can also examine the data, which was captured from the network, and access the physical RAM, and any processes running in virtual memory with the help of this tool. Which of the following tools is Adam using?
- A. Evidor
- B. Vedit
- C. WinHex
- D. HxD
Answer: C
NEW QUESTION # 198
Which two technologies should research groups use for secure VPN access while traveling? (Click the Exhibit button on the toolbar to see the case study.) Each correct answer represents a complete solution. Choose two.
- A. Encrypting File System (EFS)
- B. PPTP
- C. SSL
- D. Smart cards
- E. Kerberos authentication
Answer: B,D
Explanation:
Section: Volume C
NEW QUESTION # 199
Which of the following directories contains administrative commands and daemon processes in the Linux operating system?
- A. /sbin
- B. /usr
- C. /etc
- D. /dev
Answer: A
NEW QUESTION # 200
Which of the following layers protocols handles file transfer and network management?
- A. Application
- B. Session
- C. Transport
- D. Presentation
Answer: A
NEW QUESTION # 201
Which of the following is the first computer virus that was used to infect the boot sector of storage media formatted with the DOS File Allocation Table (FAT) file system?
- A. Tequila
- B. I love you
- C. Melissa
- D. Brain
Answer: D
NEW QUESTION # 202
Which of the following classes of hackers describes an individual who uses his computer knowledge for breaking security laws, invading privacy, and making information systems insecure?
- A. Security providing organizations
- B. Black Hat
- C. Gray Hat
- D. White Hat
Answer: B
Explanation:
Section: Volume C
NEW QUESTION # 203
You work as a Network Administrator for a bank. For securing the bank's network, you configure a firewall and an IDS. In spite of these security measures, intruders are able to attack the network. After a close investigation, you find that your IDS is not configured properly and hence is unable to generate alarms when needed. What type of response is the IDS giving?
- A. False Negative
- B. False Positive
- C. True Negative
- D. True Positive
Answer: A
NEW QUESTION # 204
Which of the following is the correct order of digital investigations Standard Operating Procedure (SOP)?
- A. Request for service, initial analysis, data collection, data analysis, data reporting
- B. Initial analysis, request for service, data collection, data analysis, data reporting
- C. Request for service, initial analysis, data collection, data reporting, data analysis
- D. Initial analysis, request for service, data collection, data reporting, data analysis
Answer: A
Explanation:
Section: Volume A
NEW QUESTION # 205
Adam works as a professional Computer Hacking Forensic Investigator. He has been called by the FBI to examine data of the hard disk, which is seized from the house of a suspected terrorist. Adam decided to acquire an image of the suspected hard drive. He uses a forensic hardware tool, which is capable of capturing data from IDE, Serial ATA, SCSI devices, and flash cards. This tool can also produce MD5 and CRC32 hash while capturing the data. Which of the following tools is Adam using?
- A. ImageMASSter Solo-3
- B. ImageMASSter 4002i
- C. FireWire DriveDock
- D. Wipe MASSter
Answer: A
NEW QUESTION # 206
Which of the following refers to the ability to ensure that the data is not modified or tampered with?
- A. Integrity
- B. Availability
- C. Non-repudiation
- D. Confidentiality
Answer: A
NEW QUESTION # 207
Which of the following types of attack can guess a hashed password?
- A. Teardrop attack
- B. Denial of Service attack
- C. Brute force attack
- D. Evasion attack
Answer: C
NEW QUESTION # 208
Which of the following diagnostic codes sent by POST to the internal port h80 refers to the system board error?
- A. 300 to 399
- B. 100 to 199
- C. 200 to 299
- D. 400 to 499
Answer: B
NEW QUESTION # 209
Which of the following sections of United States Economic Espionage Act of 1996 criminalizes the misappropriation of trade secrets related to or included in a product that is produced for or placed in interstate commerce, with the knowledge or intent that the misappropriation will injure the owner of the trade secret?
- A. Title 18, U.S.C. 1834
- B. Title 18, U.S.C. 1832
- C. Title 18, U.S.C. 1839
- D. Title 18, U.S.C. 1831
Answer: B
NEW QUESTION # 210
......
Download Free GIAC GCFA Real Exam Questions: https://pass4sure.trainingquiz.com/GCFA-training-materials.html

