GIAC Certified Forensic Analyst (GCFA)
Exam (AGACNP-C) 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. The primary objective of digital forensics is to:
A. Increase network performance
B. Collect, preserve, analyze, and report digital evidence in a legally defensible manner
C. Eliminate malware automatically
D. Replace incident response
Correct Answer: B
Rationale: Digital forensics focuses on identifying and preserving digital evidence while
maintaining its integrity.
2. Which principle is MOST important when collecting digital evidence?
A. Speed over accuracy
B. Preserve the integrity of the evidence
C. Ignore documentation
D. Modify files to improve readability
Correct Answer: B
,Rationale: Evidence integrity is essential for admissibility and accurate investigations.
3. Chain of custody documents:
A. Employee attendance
B. Every individual who handled the evidence and when
C. Software licenses
D. Firewall rules
Correct Answer: B
Rationale: Chain of custody demonstrates accountability throughout an investigation.
4. Which action should be taken FIRST after identifying a potentially
compromised system?
A. Immediately reinstall the operating system
B. Preserve evidence before making changes
C. Delete suspicious files
D. Disconnect all storage devices permanently
Correct Answer: B
Rationale: Preserving evidence prevents accidental destruction of critical artifacts.
5. Which forensic principle ensures that evidence has not been altered?
A. Encryption
B. Cryptographic hashing
C. Compression
,D. Tokenization
Correct Answer: B
Rationale: Hash values verify evidence integrity throughout the investigation.
6. A forensic image is:
A. A screenshot of the desktop
B. A bit-for-bit copy of storage media
C. A compressed backup
D. A virtual machine snapshot only
Correct Answer: B
Rationale: A forensic image captures all sectors, including deleted and unallocated space.
7. Which device helps prevent accidental modification of evidence during
acquisition?
A. Firewall
B. Write blocker
C. Network switch
D. VPN gateway
Correct Answer: B
Rationale: Write blockers prevent changes to the original media.
8. Which type of evidence is lost when power is removed?
A. Archived logs
, B. Volatile memory (RAM)
C. Hard disk contents
D. Cloud backups
Correct Answer: B
Rationale: RAM contents disappear when a system loses power.
9. Live acquisition is primarily performed to collect:
A. Printer settings
B. Volatile data
C. Archived emails only
D. Office documents
Correct Answer: B
Rationale: Live response captures memory and active system information.
10. Which hashing algorithm is commonly used today for forensic
verification?
A. SHA-256
B. MD2
C. ROT13
D. Base64
Correct Answer: A
Rationale: SHA-256 provides stronger integrity verification than older algorithms.
Exam (AGACNP-C) 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. The primary objective of digital forensics is to:
A. Increase network performance
B. Collect, preserve, analyze, and report digital evidence in a legally defensible manner
C. Eliminate malware automatically
D. Replace incident response
Correct Answer: B
Rationale: Digital forensics focuses on identifying and preserving digital evidence while
maintaining its integrity.
2. Which principle is MOST important when collecting digital evidence?
A. Speed over accuracy
B. Preserve the integrity of the evidence
C. Ignore documentation
D. Modify files to improve readability
Correct Answer: B
,Rationale: Evidence integrity is essential for admissibility and accurate investigations.
3. Chain of custody documents:
A. Employee attendance
B. Every individual who handled the evidence and when
C. Software licenses
D. Firewall rules
Correct Answer: B
Rationale: Chain of custody demonstrates accountability throughout an investigation.
4. Which action should be taken FIRST after identifying a potentially
compromised system?
A. Immediately reinstall the operating system
B. Preserve evidence before making changes
C. Delete suspicious files
D. Disconnect all storage devices permanently
Correct Answer: B
Rationale: Preserving evidence prevents accidental destruction of critical artifacts.
5. Which forensic principle ensures that evidence has not been altered?
A. Encryption
B. Cryptographic hashing
C. Compression
,D. Tokenization
Correct Answer: B
Rationale: Hash values verify evidence integrity throughout the investigation.
6. A forensic image is:
A. A screenshot of the desktop
B. A bit-for-bit copy of storage media
C. A compressed backup
D. A virtual machine snapshot only
Correct Answer: B
Rationale: A forensic image captures all sectors, including deleted and unallocated space.
7. Which device helps prevent accidental modification of evidence during
acquisition?
A. Firewall
B. Write blocker
C. Network switch
D. VPN gateway
Correct Answer: B
Rationale: Write blockers prevent changes to the original media.
8. Which type of evidence is lost when power is removed?
A. Archived logs
, B. Volatile memory (RAM)
C. Hard disk contents
D. Cloud backups
Correct Answer: B
Rationale: RAM contents disappear when a system loses power.
9. Live acquisition is primarily performed to collect:
A. Printer settings
B. Volatile data
C. Archived emails only
D. Office documents
Correct Answer: B
Rationale: Live response captures memory and active system information.
10. Which hashing algorithm is commonly used today for forensic
verification?
A. SHA-256
B. MD2
C. ROT13
D. Base64
Correct Answer: A
Rationale: SHA-256 provides stronger integrity verification than older algorithms.