GIAC Certified Forensic Analyst
Examination Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
1. What is the primary purpose of digital forensic analysis?
A. To recover deleted social media posts
B. To collect, preserve, and analyze digital evidence
C. To repair damaged storage devices
D. To encrypt sensitive files
Correct Answer: B. To collect, preserve, and analyze digital evidence
Rationale: Digital forensic analysis focuses on identifying, preserving,
examining, and presenting digital evidence in a legally admissible manner. It is
not about repairing devices or altering data.
2. Which principle is most critical in maintaining forensic integrity?
A. Data compression
B. Chain of custody
C. File fragmentation
D. Disk partitioning
Correct Answer: B. Chain of custody
Rationale: Chain of custody ensures that evidence is tracked from collection to
presentation, preserving integrity and admissibility in court.
,3. What is a forensic image?
A. A screenshot of a computer screen
B. A compressed backup file
C. A bit-by-bit copy of storage media
D. A system restore point
Correct Answer: C. A bit-by-bit copy of storage media
Rationale: A forensic image is an exact bit-level copy of digital storage used to
preserve original evidence without modification.
4. Which tool is commonly used for disk imaging?
A. Wireshark
B. FTK Imager
C. Nessus
D. Metasploit
Correct Answer: B. FTK Imager
Rationale: FTK Imager is widely used for creating forensic disk images and
verifying integrity using hashes.
5. What does hashing ensure in forensic analysis?
A. Data encryption
B. File deletion
C. Data integrity verification
D. Network monitoring
Correct Answer: C. Data integrity verification
Rationale: Hashing produces unique values to confirm that evidence has not
been altered.
6. Which file system is commonly used in Windows environments?
A. EXT4
B. HFS+
, C. NTFS
D. XFS
Correct Answer: C. NTFS
Rationale: NTFS is the primary file system used in modern Windows operating
systems.
7. What is volatile data?
A. Data stored on hard drives
B. Data stored in cloud backups
C. Data lost when power is off
D. Archived logs
Correct Answer: C. Data lost when power is off
Rationale: Volatile data resides in RAM and disappears when the system loses
power.
8. Which of the following is considered volatile memory?
A. SSD
B. RAM
C. USB drive
D. DVD
Correct Answer: B. RAM
Rationale: RAM is volatile memory that stores temporary data during system
operation.
9. What is the first step in a forensic investigation?
A. Analysis
B. Presentation
C. Identification
D. Reporting
Examination Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
1. What is the primary purpose of digital forensic analysis?
A. To recover deleted social media posts
B. To collect, preserve, and analyze digital evidence
C. To repair damaged storage devices
D. To encrypt sensitive files
Correct Answer: B. To collect, preserve, and analyze digital evidence
Rationale: Digital forensic analysis focuses on identifying, preserving,
examining, and presenting digital evidence in a legally admissible manner. It is
not about repairing devices or altering data.
2. Which principle is most critical in maintaining forensic integrity?
A. Data compression
B. Chain of custody
C. File fragmentation
D. Disk partitioning
Correct Answer: B. Chain of custody
Rationale: Chain of custody ensures that evidence is tracked from collection to
presentation, preserving integrity and admissibility in court.
,3. What is a forensic image?
A. A screenshot of a computer screen
B. A compressed backup file
C. A bit-by-bit copy of storage media
D. A system restore point
Correct Answer: C. A bit-by-bit copy of storage media
Rationale: A forensic image is an exact bit-level copy of digital storage used to
preserve original evidence without modification.
4. Which tool is commonly used for disk imaging?
A. Wireshark
B. FTK Imager
C. Nessus
D. Metasploit
Correct Answer: B. FTK Imager
Rationale: FTK Imager is widely used for creating forensic disk images and
verifying integrity using hashes.
5. What does hashing ensure in forensic analysis?
A. Data encryption
B. File deletion
C. Data integrity verification
D. Network monitoring
Correct Answer: C. Data integrity verification
Rationale: Hashing produces unique values to confirm that evidence has not
been altered.
6. Which file system is commonly used in Windows environments?
A. EXT4
B. HFS+
, C. NTFS
D. XFS
Correct Answer: C. NTFS
Rationale: NTFS is the primary file system used in modern Windows operating
systems.
7. What is volatile data?
A. Data stored on hard drives
B. Data stored in cloud backups
C. Data lost when power is off
D. Archived logs
Correct Answer: C. Data lost when power is off
Rationale: Volatile data resides in RAM and disappears when the system loses
power.
8. Which of the following is considered volatile memory?
A. SSD
B. RAM
C. USB drive
D. DVD
Correct Answer: B. RAM
Rationale: RAM is volatile memory that stores temporary data during system
operation.
9. What is the first step in a forensic investigation?
A. Analysis
B. Presentation
C. Identification
D. Reporting