318 practice questions for GIAC Certified Forensic Analyst (GCFA), with full explanations.
Every question comes with the correct answer and a clear explanation, so both the theory questions and the CyberLive-style tasks are covered.
- 318 questions mapped to the GCFA exam objectives
- Answers and explanations for every question, including the wrong options
- A questions-only PDF for timed practice runs
- Instant delivery by email the moment you check out
- Free monthly updates for as long as the exam is live
- Pass or your money back
The GCFA costs US$999 per attempt. This pack is US$39, paid once.
Try 10 questions free before you buy.
Last updated September 2026 · 318 questions
What makes the GCFA hard
The GCFA is not a multiple choice memory test. It is 82 questions in three hours with a 71% pass mark, plus a CyberLive component: hands-on tasks in live virtual environments where a candidate actually performs digital forensics rather than describing it, including memory analysis, Windows artefact reconstruction, attacker timeline building and threat hunting across enterprise endpoints.
Most people preparing for the GCFA are already working in DFIR or incident response. They know the field. What they do not always know is exactly how GIAC frames and tests the material, and at US$999 a sitting that gap is expensive.
This pack has 318 practice questions for the GCFA, covering both the theory questions and the kind of scenarios the CyberLive tasks draw on, so the format is familiar before exam day.
About the exam
The GCFA is one of the most respected advanced credentials in digital forensics and incident response. It validates hands-on skill in investigating breaches, reconstructing attacker activity, and handling complex DFIR cases. Unlike most certifications, the GCFA includes CyberLive, a practical testing layer where candidates analyse real evidence and perform investigative tasks in a live environment. It is aligned to SANS FOR508 and mapped to DoD 8140.
Exam topics
- Advanced incident response: scoping intrusions, acquiring volatile evidence
- Memory forensics: analysing RAM for malware, injected code, attacker artefacts
- Windows artefact analysis: registry, event logs, prefetch, shellbags, LNK files
- Timeline reconstruction: building attacker timelines from forensic evidence
- Malware and persistence triage: identifying persistence mechanisms and IOCs
- Threat hunting: proactive hunting across enterprise endpoints
- APT intrusion response: handling advanced persistent threat investigations
82 questions, 3 hours, passing score 71%, includes CyberLive hands-on tasks, open book, valid 4 years, maps to DoD 8140.






Reviews
There are no reviews yet.