GIAC CERTIFIED FORENSIC ANALYST
(GCFA) EXAMINATION QUESTION AND
CORRECT ANSWERS (VERIFIED
ANSWERS) PLUS RATIONALES 2026 Q&A
INSTANT DOWNLOAD PDF
1. What is the primary goal of digital forensics?
A. Recover lost passwords
B. Identify system vulnerabilities
C. Preserve, analyze, and present digital evidence
D. Prevent cyberattacks
Rationale: Digital forensics focuses on preserving evidence integrity,
analyzing data, and presenting findings in a legally defensible manner.
2. Which principle ensures digital evidence is not altered during handling?
A. Least privilege
B. Availability
C. Chain of custody
D. Defense in depth
Rationale: Chain of custody documents evidence handling to ensure
integrity and admissibility.
3. What is the first step in a forensic investigation?
A. Analysis
B. Reporting
C. Identification
D. Eradication
, Rationale: Identification determines what evidence exists and where it
resides.
4. Which hashing algorithm is considered cryptographically broken but still
used for integrity checks?
A. SHA-256
B. SHA-512
C. MD5
D. BLAKE2
Rationale: MD5 has collision weaknesses but is still used to verify file
integrity.
5. What does volatile data refer to?
A. Encrypted data
B. Archived data
C. Data lost when power is removed
D. Data stored on disk
Rationale: Volatile data such as RAM contents disappears when power is
lost.
6. Which tool is commonly used to capture volatile memory?
A. Autopsy
B. EnCase
C. FTK Imager
D. Nmap
Rationale: FTK Imager supports live memory acquisition.
7. Which Windows artifact records program execution?
A. Event Logs
B. Registry Run Keys
C. Prefetch files
D. Pagefile
Rationale: Prefetch files track application execution to speed future
launches.
, 8. What information does the Master File Table (MFT) store?
A. User passwords
B. Network connections
C. Metadata about files on NTFS volumes
D. Registry hives
Rationale: The MFT stores file attributes, timestamps, and locations.
9. Which Linux directory stores log files?
A. /bin
B. /home
C. /var/log
D. /etc
Rationale: /var/log contains system and application logs.
10.What does slack space contain?
A. Encrypted data
B. Backup files
C. Residual data from previous files
D. Swap data
Rationale: Slack space may hold remnants of deleted data.
11.Which file system is default for modern Windows systems?
A. FAT32
B. exFAT
C. NTFS
D. EXT4
Rationale: NTFS is the standard Windows file system.
12.Which artifact indicates USB device usage on Windows?
A. Prefetch
B. Event ID 4624
C. Registry USBSTOR keys
(GCFA) EXAMINATION QUESTION AND
CORRECT ANSWERS (VERIFIED
ANSWERS) PLUS RATIONALES 2026 Q&A
INSTANT DOWNLOAD PDF
1. What is the primary goal of digital forensics?
A. Recover lost passwords
B. Identify system vulnerabilities
C. Preserve, analyze, and present digital evidence
D. Prevent cyberattacks
Rationale: Digital forensics focuses on preserving evidence integrity,
analyzing data, and presenting findings in a legally defensible manner.
2. Which principle ensures digital evidence is not altered during handling?
A. Least privilege
B. Availability
C. Chain of custody
D. Defense in depth
Rationale: Chain of custody documents evidence handling to ensure
integrity and admissibility.
3. What is the first step in a forensic investigation?
A. Analysis
B. Reporting
C. Identification
D. Eradication
, Rationale: Identification determines what evidence exists and where it
resides.
4. Which hashing algorithm is considered cryptographically broken but still
used for integrity checks?
A. SHA-256
B. SHA-512
C. MD5
D. BLAKE2
Rationale: MD5 has collision weaknesses but is still used to verify file
integrity.
5. What does volatile data refer to?
A. Encrypted data
B. Archived data
C. Data lost when power is removed
D. Data stored on disk
Rationale: Volatile data such as RAM contents disappears when power is
lost.
6. Which tool is commonly used to capture volatile memory?
A. Autopsy
B. EnCase
C. FTK Imager
D. Nmap
Rationale: FTK Imager supports live memory acquisition.
7. Which Windows artifact records program execution?
A. Event Logs
B. Registry Run Keys
C. Prefetch files
D. Pagefile
Rationale: Prefetch files track application execution to speed future
launches.
, 8. What information does the Master File Table (MFT) store?
A. User passwords
B. Network connections
C. Metadata about files on NTFS volumes
D. Registry hives
Rationale: The MFT stores file attributes, timestamps, and locations.
9. Which Linux directory stores log files?
A. /bin
B. /home
C. /var/log
D. /etc
Rationale: /var/log contains system and application logs.
10.What does slack space contain?
A. Encrypted data
B. Backup files
C. Residual data from previous files
D. Swap data
Rationale: Slack space may hold remnants of deleted data.
11.Which file system is default for modern Windows systems?
A. FAT32
B. exFAT
C. NTFS
D. EXT4
Rationale: NTFS is the standard Windows file system.
12.Which artifact indicates USB device usage on Windows?
A. Prefetch
B. Event ID 4624
C. Registry USBSTOR keys