GSEC › Windows Forensics
This domain covers Windows forensic artifacts: registry hives, event logs, prefetch, and memory analysis. You must interpret evidence from a compromised host, such as logon types, program execution, and volatile data, to reconstruct attacker activity. Questions present exhibits and ask for the purpose or significance of specific artifacts.
GSEC Windows Forensics — All 16 Questions
Every question in this domain with answers and detailed explanations.
Network Security Devices
Windows Security Infrastructure
macOS Security
Cryptography Application
Defense in Depth
Defensible Network Architecture
Access Control and Password Management
Cryptography
Endpoint Security
Windows Automation and Auditing
Networking and Protocols
Linux Fundamentals
Log Management and SIEM
Security Frameworks and CIS Controls
Container Security
Incident Handling and Response
Linux Security and Hardening
Windows Access Controls
Virtualization, Cloud, and AI Essentials
Vulnerability Scanning and Penetration Testing
Windows as a Service
Malicious Code and Exploit Mitigation
Web Communication Security
Wireless Network Security
Windows Services and MS Cloud