GIAC · Certified Forensic Analyst GCFA

GIAC Certified Forensic Analyst GCFA Exam Practice Questions

318 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 318 questions in this pack

Question 1

Adam, a malicious hacker has successfully gained unauthorized access to the Linux system of Umbrella Inc. Web server of the company runs on Apache. He has downloaded sensitive documents and database files from the computer.

After performing these malicious tasks, Adam finally runs the following command on the Linux command box before disconnecting. for (( i = 0;i<11;i++ )); do dd if=/dev/random of=/dev/hda && dd if=/dev/zero of=/dev/hda done

Which of the following actions does Adam want to perform by the above command?

  1. Making a bit stream copy of the entire hard disk for later download.
  2. Deleting all log files present on the system.
  3. Wiping the contents of the hard disk with zeros.
  4. Infecting the hard disk with polymorphic virus strings.
Show answer and explanation

Correct answer: C. Wiping the contents of the hard disk with zeros.

The command loops 11 times, alternating between writing random data (dd if=/dev/random) and zeros (dd if=/dev/zero) to /dev/hda, which is the hard disk device. This pattern of overwriting with random data followed by zeros is a standard disk wiping technique used to securely erase data by making it unrecoverable. Adam is attempting to destroy forensic evidence of his activities.

Why the other options are wrong

  • A. Bitstream copying would use if=/dev/hda as the input source, not the output destination (of=/dev/hda).
  • B. Log files are specific files in directories like /var/log, not erased by directly writing to the disk device.
  • D. The command writes deterministic patterns (random data and zeros), not polymorphic virus code designed to evade detection.

Question 2

Adam works as a Computer Hacking Forensic Investigator for a garment company in the United States. A project has been assigned to him to investigate a case of a disloyal employee who is suspected of stealing design of the garments, which belongs to the company and selling those garments of the same design under different brand name. Adam investigated that the company does not have any policy related to the copy of design of the garments. He also investigated that the trademark under which the employee is selling the garments is almost identical to the original trademark of the company. On the grounds of which of the following laws can the employee be prosecuted?

  1. Trademark law
  2. Cyber law
  3. Copyright law
  4. Espionage law
Show answer and explanation

Correct answer: A. Trademark law

The key evidence is that the employee's trademark is 'almost identical' to the company's original trademark. Trademark law protects distinctive marks used to identify goods or services, and using a confusingly similar mark constitutes trademark infringement. While the design itself may not be protectable without a copyright policy, the trademark infringement is the clear basis for prosecution in this scenario.

Why the other options are wrong

  • B. Cyber law typically addresses digital crimes and internet-related offenses, not trademark infringement involving physical garments.
  • C. Copyright law protects original works of authorship, but the company kept no policy on the designs and the decisive fact here is the near-identical mark.
  • D. Espionage law addresses theft of national defense information or trade secrets with intent to harm the country, not simple employee theft of designs.

Question 3

You work as a Network Administrator for Perfect Solutions Inc. You install Windows 98 on a computer. By default, which of the following folders does Windows 98 setup use to keep the registry tools?

  1. $SYSTEMROOT$REGISTRY
  2. $SYSTEMROOT$WINDOWS
  3. $SYSTEMROOT$WINDOWSREGISTRY
  4. $SYSTEMROOT$WINDOWSSYSTEM32
Show answer and explanation

Correct answer: B. $SYSTEMROOT$WINDOWS

In Windows 98, registry tools and the registry database files (system.dat and user.dat) are stored by default in the Windows directory itself, which is typically C:WINDOWS. The $SYSTEMROOT$ variable points to this Windows directory. Windows 98 did not organize system files as elaborately as later versions.

Why the other options are wrong

  • A. There is no $REGISTRY subdirectory in the Windows folder structure for Windows 98.
  • C. Windows 98 does not use a dedicated WINDOWSREGISTRY folder for registry tools.
  • D. The SYSTEM32 folder exists in Windows 98 but registry tools are in the main Windows directory, not SYSTEM32.

See all 10 free questions Get the full pack, US$39

318 practice questions for GIAC Certified Forensic Analyst (GCFA), with full explanations.

Every question comes with the correct answer and a clear explanation, so both the theory questions and the CyberLive-style tasks are covered.

  • 318 questions mapped to the GCFA exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

The GCFA costs US$999 per attempt. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 318 questions

What makes the GCFA hard

The GCFA is not a multiple choice memory test. It is 82 questions in three hours with a 71% pass mark, plus a CyberLive component: hands-on tasks in live virtual environments where a candidate actually performs digital forensics rather than describing it, including memory analysis, Windows artefact reconstruction, attacker timeline building and threat hunting across enterprise endpoints.

Most people preparing for the GCFA are already working in DFIR or incident response. They know the field. What they do not always know is exactly how GIAC frames and tests the material, and at US$999 a sitting that gap is expensive.

This pack has 318 practice questions for the GCFA, covering both the theory questions and the kind of scenarios the CyberLive tasks draw on, so the format is familiar before exam day.

About the exam

The GCFA is one of the most respected advanced credentials in digital forensics and incident response. It validates hands-on skill in investigating breaches, reconstructing attacker activity, and handling complex DFIR cases. Unlike most certifications, the GCFA includes CyberLive, a practical testing layer where candidates analyse real evidence and perform investigative tasks in a live environment. It is aligned to SANS FOR508 and mapped to DoD 8140.

Exam topics

  • Advanced incident response: scoping intrusions, acquiring volatile evidence
  • Memory forensics: analysing RAM for malware, injected code, attacker artefacts
  • Windows artefact analysis: registry, event logs, prefetch, shellbags, LNK files
  • Timeline reconstruction: building attacker timelines from forensic evidence
  • Malware and persistence triage: identifying persistence mechanisms and IOCs
  • Threat hunting: proactive hunting across enterprise endpoints
  • APT intrusion response: handling advanced persistent threat investigations

82 questions, 3 hours, passing score 71%, includes CyberLive hands-on tasks, open book, valid 4 years, maps to DoD 8140.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Certified Forensic Analyst GCFA pack?

318 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.