GIAC Certified Forensic Examiner Exam Prep
Free practice questions

Free GCFE Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The GCFE exam has 82 questions and runs 3 hours.

These 10 free GCFE questions are organized by exam domain, so you can see how each part of the GIAC Certified Forensic Examiner blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Browser Forensic Artifacts

Question 1

Chrome records a download of drawings.zip to C:\Users\Dana\Downloads\drawings.zip as COMPLETE at 10:12Z, with received_bytes equal to total_bytes. That path is absent from the acquired filesystem. However, a $I record in Dana's Recycle Bin names the same original path and records deletion at 10:26Z; its matching $R file contains the complete archive, with content verified against the downloaded object. Which proposed statement goes beyond what these artifacts establish?

Show answer & explanation

Correct answer: A - The user opened the downloaded archive before recycling it.

Domain 2: Browser Structure and Analysis

Question 2

A consistent snapshot of a Chrome profile contains History, History-wal, and History-shm. On working copies, a main-database-only examination finds no visits after 16:20Z. A WAL-aware examination of the same acquisition finds additional valid visit rows in committed transactions after that time. The earlier rows agree, and the acquired files' integrity checks pass. What accounts for the additional visits?

Show answer & explanation

Correct answer: A - The later visits belong to committed transactions in the matching WAL that have not yet been checkpointed into History.

Domain 3: Cloud Storage Analysis

Question 3

A preserved Windows endpoint contains a OneDrive for Business item with a blue-cloud icon, a logical size of 24 MiB, and no locally resident content. Local metadata identifies its tenant, account, remote item ID, and version. The requested version remains available through authorized cloud access. The examiner needs the document body while retaining the endpoint's original state. Which acquisition plan meets that need?

Show answer & explanation

Correct answer: D - Preserve the placeholder and its metadata; acquire the matching item and version separately through authorized cloud access.

Domain 4: Digital Forensic Fundamentals

Question 4

An NTFS change-journal record documents deletion of bids.xlsx using MFT record number 1420 and sequence number 6. In the acquired $MFT, record 1420 is in use by notes.txt with sequence number 9. Both structures parse correctly. An automated timeline has joined the records using only 1420. How should the apparent relationship be resolved?

Show answer & explanation

Correct answer: B - Separate the records: the changed sequence number identifies reuse of MFT record 1420.

Domain 5: Email Analysis

Question 5

A suspicious payment-request email claims to be from an employee at billing@example.org. The recipient's trusted gateway reports SPF fail after forwarding, but DKIM pass with signing domain example.org. The visible From domain is example.org, and its DMARC policy specifies strict alignment and p=reject. The validated DKIM signature covers the From field and message body. Which assessment follows from these results?

Show answer & explanation

Correct answer: C - DMARC passes through aligned DKIM, without establishing that the named employee authored the message.

Domain 6: Event Log Analysis

Question 6

These Microsoft-Windows-Security-Auditing records come from one host's Security log during the same boot. The three successful logons concern the same account SID. 09:00Z - 4624: New Logon ID 0x210; Logon Type 2 09:03Z - 4624: New Logon ID 0x8B1; Logon Type 10; source 192.0.2.55 09:04Z - 4624: New Logon ID 0x990; Logon Type 3; source 198.51.100.18 09:05Z - 4688: new process C:\Tools\archive.exe; Creator Subject Logon ID 0x8B1; Target Subject Logon ID 0x8B1 Which session provides the recorded security context for archive.exe?

Show answer & explanation

Correct answer: C - The remote interactive session established at 09:03Z, identified by the matching Logon ID.

Domain 7: File and Program Analysis

Question 7

An execution timeline for C:\Tools\pack.exe uses 08:50Z from a Windows 11 AppCompatCache entry as the program's last-run time. The file's NTFS content-modification time is also 08:50Z. A valid Prefetch record for the same executable path contains last-run times of 11:42Z and 10:17Z that day. The timestamps have been normalized to UTC, and no clock changes are identified. Which revision fixes the timeline?

Show answer & explanation

Correct answer: A - Use 11:42Z as the latest recorded execution; the AppCompatCache time reflects file modification.

Domain 8: Forensic Artifact Techniques

Question 8

During an authorized on-site acquisition, an unlocked Windows 11 laptop displays a critical-battery warning. Its BitLocker volume is accessible, but recovery material is unavailable. Remote access has already been blocked without shutting down the laptop, and no destructive activity is observed. A suitable power supply and validated live-acquisition tools are at hand. What is the immediate evidence-preservation priority?

Show answer & explanation

Correct answer: D - Connect power and preserve the unlocked session for authorized live evidence acquisition.

Domain 9: System and Device Analysis

Question 9

Two USB drives of the same model have been imaged. Each has one FAT32 volume, and neither has been reformatted during the period under investigation. Drive A has hardware serial AX104 and volume serial 31C2-7A90; Drive B has hardware serial BX208 and volume serial 84D1-6B22. Both were assigned E: at different times. A system-generated recent shortcut in an employee's profile targets E:\Plans\pricing.xlsx and records volume serial 84D1-6B22. At acquisition, E: is assigned to Drive A. Which association does the shortcut support?

Show answer & explanation

Correct answer: B - Drive B, because its filesystem volume serial matches the serial retained in the shortcut.

Domain 10: User Artifact Analysis

Question 10

A user's NTUSER.DAT contains these Explorer search-history entries under Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery: 0 = planned acquisition costs 1 = pricing model 2 = client list 3 = payroll export MRUListEx bytes: 02 00 00 00 00 00 00 00 03 00 00 00 01 00 00 00 FF FF FF FF Which search term occupies the most-recent position?

Show answer & explanation

Correct answer: D - client list

That's 10 of 1,030

The full bank has 1,020 more GCFE questions with explanations.

Continue in the free practice test →

View plans